PI IP Flow Interface

From SCADApedia

Jump to: navigation, search

General

Routers and switches from many vendors provide NetFlow, sFlow or IPFIX data. This data is sent to a collection point where and administrator can view information about the network. The following information is typically collected: Source Address, Source Port, Source MAC, Destination Address, Destination Port, Destination MAC, IP Protocol, Number of bytes.

The flow data can then be sent to a PI IP Flow interface. The IP Flow interface then sends the data to the PI server for analysis.


Impact

In the PCS arena, analysis of data from the IP Flow interface can show trends in the amount of traffic on the network, new systems on the network and unusual network behavior. The information can be used to determine if an attacker is scanning the network or if the PLCs are generating more traffic because there is a problem on a device.


External Links

OSIsoft

OSIsoft PI IT Monitor

Personal tools