To be written.
The first page you see is the setup. In the upper left you may provide your user name and password, and log in. At this page you can choose either to create an overview or a specific observation point report. Click the tab of your choice.

Overview
Report.

Specific
Observation Point Report.
In essence the
Overview Report tab let you get a report with a row of data for each observation point.
Single Observation Point lets you create a report with one single observation point for a single time period.
The settings of the setup screens are mostly quite intuitive. However, the “Show inactive” check box could need a little explanation. By checking it observation points that have been active earlier, but that are currently inactive will be included in the report as well.
The “Create report” button displays the report in the main Stager page. The setup page is normally only used for the initial report. It would be natural to create the next reports directly from the main Stager page.
At the setup page you are also allowed to perform a full reset of your Stager session. If you are experiencing trouble generating a report this could be the trick. Only your ongoing session with Stager is affected by the reset function.
Table of Contents To be updated!
The report page is divided in two sections. The navigation in top, and the main in which presents the reports as table data or plots. The results of the actions taken in the navigation part are rendered in the main part. In this chapter you will learn how to navigate effectively in Stager.
We start by introducing time navigation. Navigation in time includes traversal back and forth in time periods. Supported time resolutions range from hours to months.
Stager makes it easy to set up reports, even for beginners. This is due to the use of drop down menus. All possible settings appear in these menus. No need to type in anything. The report type, the transformation and the view of the report has to be selected. In addition you will have to select the group of observation points or the specific you want the report for. As all these settings are set you can choose either to show the report or to add it to the current one(s).
Reports can be visualized using graphs. Making rough comparisions far easier. Stager supports both pie charts and line plots (and probably bar plots soon), enabling you to peek at the data of a current point in time, or observe it as it develops over time.
There are filter and sort functionality that ease the task of getting the information you are looking for.
The navigation among reports is taken to the next level by the context menu introduced in release 3 of Stager. A context menu can be called on almost all data elements of a report, giving you several choices related to that element, ranging from general filtering to more specific functionality.
To navigate in time you must understand the concept and difference of time periods and time resolutions. A default installation of Stager may contain time resolutions including hour, day, week and month. Before moving on let us clearify what resolution is. The highest resolution is the shortest period of time, but is at the lowest level. It can be compared to climbing a ladder. At the bottom level you can see every tiny detail of the ground beneath you. The resolution is high. By going up a few steps, your view will widen. You see more, but at expense of some detail. Hence the resolution is reduced as you are going up. The opposite comes true climbing down the ladder. Lower level, higher resolution.
In the week resolution time period you are shown data for one week at a time. The data for a week is aggregated from the data of seven days. Likewise data for day resolution is aggregated from 24 hours. Some statistics are not available at the lowest level, like min, max, standard deviance and variance coeffesient. Plotting line and area graphs are not possible at the lowest level, because these graph types plot data during a period; an approach in which uses data from the level below.

Time
navigation buttons.
To go to a higher level time period, use the arrow pointing upwards. Going to a lower level requires you to select what part of the current time period you want to zoom into. Let us say you are currently in week resolution, then the drop down menu will let you choose among the days of the week.
For traversal back and forth in time, changing the time period, the user can use the single or double arrows in the time navigation bar. Single arrows bring you to the next or previous time period. For example, if you are on Monday, then the next button would take you to Tuesday. A double arrow takes you to the next or previous time period jumping in steps of the time resolution above. If currently on Monday, the double right arrow would move you to the Monday next week.
The calendar displays the last five months, and lets you go directly to a specific date. In hour resolution you are taken to the first hour of the selected date. In week and month resolution you are taken to the week or month of the day, respectively. The calendar is displayed by clicking the calendar icon.
![]()
Calendar
icon.

Calendar.
Different types of data distribution is available
in different reports. The IP protocol report for example
shows the distribution of traffic between different IP protocols,
like TCP, UDP, ICMP etc. Much
data is available for each report. Examples are total octets, average
octets, average package size and number of flows per second. It would
not be possible to display all information at the same time in a
reasonable way. Different transformations show different subsets of
data. Transformations are discussed in the next section.
The set of predefined reports available in the default installation includes:
Summary
Multicast Summary
Interface
Destination AS
Destination Port
Source Port
Protocol
Multicast Src AS
Multicast Src IP
Multicast Groups
Source IP
Destination IP
Src/Dst AS
Src/Dst IP
Source AS
Note: Some of these reports require the user to be logged in..
The report type is choosen from the drop down menu marked below.

Report
types.
The different report types will be explained in the next chapter. In addition we will describe the transformations of the reports.
A report has one or more transformations. A transformation represents a subset of the available statistics for a report. The summary transformation displays a summary of the report. In the overview transformation several observation points or interfaces are used, making it easy to make comparisions. The table is usually used to present data for a particular observation point. And the global transformation is another sort of overview. The different transformations defined are:
Summary
Overview
Table
Matrix
Global
Transformations are selected using the marked drop down menu:

Transformations.
In some reports there are several views available. The standard view presents summary statistics about octets, packets and flows, and is kind of an overview. Many reports offer additional views. These views usually are more specific. Examples are detailed views for octets, packets and flows. What views are available actually depend on what report and transformation that is selected.
Setting the view is done in the marked drop down menu as shown below.

Views.
Sometimes there is no reason to display all rows. This can be constrained by setting a maximum row limit. The row limit is set in the marked drop down menu as shown below.

Row
limit.
The observation point is selected by the drop down menus on the second line. The first one sets the group of observation points. The next sets the observation point. And the last one sets the direction of the traffic. Not all report types let you select observation point. An overview report for example shows a whole group of observation points.
![]()
Setting
observation point(s).
As you have made the settings for the report and the observation point, it is time create it. To display it you simply hit the show button. Be aware that if you are currently working with several reports, these will disappear. So, by clicking the show button only one report will be shown. The one just specified.

Show
report button.
Read the section “Working with multiple reports” to learn about what is important when there are several reports present at a time.
Stager allows you to filter reports. Hitting the scissors icon the filter menu will appear.
![]()
Filter
icon.
![]()
Filter
menu.
The filter menu lets you choose the column to filter, the filter operation to perform and the value to filter by. Be aware that values presented in the report often are rounded. The value “1.98k” could in fact be any value between 1975 and 1984. The filtering value must be either an integer or a decimal number. Values cannot be written in short notation as in the report. The value “1.98k” is not valid for filtering. But “1980” or “1980.0” would be perfectly OK. To disable the filters simply select none from the filter operations drop down menu. Only one filter can be used at a time for a report.
Available filter operations are:
Equals
Not equal
Greater than
Less than
None (disables filter)
Sorting reports is carried out by clicking the column titles of the report. Naturally only one column can be sorted at a time. The title background of the sorted column turns darker as an indication. Columns can either be sorted ascending or descending. First time sort of a column is ascending. Clicking the title of the sorted column once more will reverse the sort.

Graphs let you visualize your report. Stager provides two types of graphs. Pie charts and plots. Using graphs makes it much easier to compare values at a point in time, or to see the development of a value over time. Those reports supporting graphs has a setup bar right above the report table. In the rows and columns of these reports there are check boxes to check for inclusion in the graph. Make sure at least one culumn and one row is selected, else there will be no data for the graph. The graph type is selected from the drop down menu. By checking the box “Other” a group representing the sum of all rows not selected will be included in the graph. Hit the “plot graph” button to render the graph.

Setup
of graph.
The pie chart uses data from one time period, using the current time resolution. Only the first checked column is included in the pie chart. The data of the selected rows in the selected column is used to draw the pie chart.

Pie
chart.
The line plot views the data selection over time. One or more culumns can be used with the line plot. For the line plot to be able to make the plot you cannot be at the highest time resolution. It needs data from the time periods of the time resolution above. Hence the line plot is not available for the hour resolution. Line plots feature embedded links in the the graph. This is useful if you are investigating a graph at low resolution. By clicking a link you are taken to the corresponding higher resolution time period. Let us say you are in day resolution. Then there would be 24 links on the plotted line, each link representing an hour of the day.

Line
plot.
In many scenarios it is convenient to view more than one report at a time. Stager lets you easily add more reports. To add a report you simply follow the same procedure as if you were creating a single one. The difference is that you hit the add button instead of the show button. The most recently added report will be at bottom. The origin at top. A report can be either in the form of a table or graph. When adding a report you may set a time difference relative to the origin report. This could for example be useful if you would like to view the same report at different points in time. The drop down menu lets you go back in time periods, or go up to a lower resolution time period. The value sets the number of steps, respectively. For example, if you are in hour resolution and add a report with the drop down menu set to up and with the value 2, then you would get a report for the current week. Two steps up.

Add
report button.
![]()
Time
difference settings.
Clicking the delete icon in the upper right of the report will make it disappear. All reports except the origin one can be deleted.

Showing
two reports at the same time.
Using a bookmark makes it easy to return to the same report at a later time. By bookmarking a report you are returned a unique URL address that takes you directly to the report bookmarked.
![]()
Bookmark
icon.
Bookmarking frequently shown reports or groups of reports could save you lots of time. Sharing a particular report with colleagues is easily done.
The context menu is a menu that shows up when you right click an element in a report table. The choices of the menu is related to the element clicked. By calling the menu on an observation point in a report for example, a menu of available reports for that current observation point will appear. Calling the menu on an IP address will give a menu with choices regarding that IP. Filtering can also be carried out using this menu. Data fields subject to filtering yield a filter menu where you have the same filtering options as if you where using the filter bar on top. The difference is that you do not have type in the filter value when using the filters on the menu. The filter value is then set the value of the field in which the menu was called.

The
context menu in action.
By default the context menu only has support for internal navigation in Stager. However, there is no problem to extend it using custom menus. It may easily be integrated with external systems. One example of usage would be IP addresses. As long as the service can be accessed through a URL with the IP address as parameter it can be used by the context menu. Custom menus are defined in an XML file in the backend.
Note: In order for the context menu to work make sure the “Yahoo! UI Library” is installed. And be aware that not all browsers display the menu by right clicking. Opera for instance require you to hold the CTRL while clicking the left mouse button.
Table of Contents
We will first describe each available report in the section called “Report Descriptions”, then describe all types of statistics available in the section called “Types of statistics”.
This is the list of predefined reports. A local installation of Stager may differ in which reports are available.
This report shows the distribution of the traffic on the observation point selected, to the other interfaces/observation points on the same device. The internal arrows in the device shown in figure Figure 3.1, “Distribution among Destination Interfaces” try to explain the distribution.
Figure 3.1. Distribution among Destination Interfaces
![]()
The rows in the report shows traffic for each of the red interfaces/observation points shown on figure Figure 3.1, “Distribution among Destination Interfaces”.
This report shows the distribution of traffic based on which IP Protocol is used. Examples of IP Protocols are: TCP, UDP, ICMP, GRE and PIM.
This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five most used IP Protocols.
This report present the distribution of traffic based on the value of the ToS field in the IP header. The value are presented as an decimal number. Later versions of Stager probably will support displaying the values as hex.
This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five most common values of the ToS field.
This reports shows the distribution of IP Source Addresses for the selected observation point.
This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five IP Source Addresses with the most traffic measured in octets.
This reports shows the distribution of IP Destination Addresses for the selected observation point.
This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five IP Destination Addresses with the most traffic measured in octets.
This reports shows the distribution of IP Source Destination Address combinations for the selected observation point. Sorted on the pair of from/to IP address with most traffic.
This report is available in Matrix mode. In matrix mode each row/column represent a source/destination IP. In matrix mode only one type of statistic can be shown at the time. You can show octets, packets or flows.
This report shows the distribution of Source Autonomous System for the traffic at the selected observation points.
This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five Source Autonomous System with the most traffic measured in octets.
This report shows the distribution of Destination Autonomous System for the traffic at the selected observation points.
This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five Destination Autonomous System with the most traffic measured in octets.
This reports shows the distribution of Autonomous System Source Destination combinations for the selected observation point. Sorted on the pair of from/to AS with most traffic.
This report is available in Matrix mode. In matrix mode each row/column represent a source/destination AS. In matrix mode only one type of statistic can be shown at the time. You can show octets, packets or flows.
This reports shows the distribution of the source TCP/UDP (Transport Layer) ports for the traffic on the selected observation point. Each row in the report represent an source port. If your goal is to have an report of distribution of different services in your network, the destination port report below is better suited to identify such services.
This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five source TCP/UDP port with most traffic.
This reports shows the distribution of the destination TCP/UDP (Transport Layer) ports for the traffic on the selected observation point. Each row in the report represent an destination port. The destination port is mapped to a list of well knowned services. But note that this list is not absolute. Some services use a random port, other use several ports, and some even use a port which is reserved for other services.
This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five destination TCP/UDP ports with most traffic.
The percent value of each transport port is computed from the total amount of traffic. Since not all traffic is TCP/UDP traffic, and therefore have no port accociated with it, the sum of all port percentage will not add up to 100%, but will add up to the percentage of the total traffic which is TCP/UDP, which often is pretty close to 100%.
While all other reports shows observation point distribution, summary shows total statistics for an observation point, as in example total octets, total flows, flow time and average octets. The fields available in Summary reports are explained in detail in section the section called “Types of statistics”.
Almost all the reports described in the section called “Report Descriptions” have common types of statistics available, which include:
Octets - bit/s: This shows the traffic measured in bit per second. The traffic is computed by the size of IP Packets, including both headers and payload. The value is the average over the time period selected. The value is computed by dividing the total amount of traffic in the time period on the number of seconds in the period.
When the data source is sampled, the measured data is divided on the sample rate. In example a sample rate of one-out-of 100, and a measured data of 100kbps, would result in an estimated value of 10Mbps.
Octets - Total: This shows the total traffic measured for the selected time period. The traffic is computed by the size of IP Packets, including both headers and payload.
When the data source is sampled, the measured data is divided on the sample rate. In example a sample rate of one-out-of, and a measured data of 100kbit, would result in an estimated value of 10Mbit.
Octets - Percent: This shows how much traffic were measured for each specific entry divided on the total amount of traffic. The data is presented as percent values.
In example in the IP Protocol report, the TCP row entry shows how much traffic was measured as TCP traffic related to the total amount of traffic.
When the data source is sampled, both the total traffic, and the traffic for the specific entry might be inaccurate. Obviously the percent value inherit the inaccuracy.
Octets - Minimum bit/s: As explained in the User Guide, data is aggregated from the time resolution below. So data for the day resolution is aggregated from hour. Minimum value means the one of the average octet - bit per second found on the time resolution below, with the lowest value. So when data is to be aggregated for day resolution, the one of the 24 hour-resolution octet average values is selected. On week resolution, minimum bit/s means average bit/s the day with the least total traffic.
In example for month January, data is aggregated from week 1, 2, 3 and 4. Octets bit/s, for these weeks respectively is 23.4Mbps, 29.1Mbps, 17.2Mbps and 30.1Mbps. The minimum bit/s value for January is then 17.2Mbps. The minimum bit/s for week 3 is lower than 17.2Mbps assumed that the data rate is not completely constant. If the average day traffic for week 3 vary from 6Mbps to 48Mbps, then the minimum bit/s for week 3 is 6Mbps.
Octets - Maximum: Octets - Maximum is equal to minimum, expect that maximum values are used instead of minimum values.
Octets - Standard Deviation: Standard deviation is calculated from the total octets from all the time periods contained in the same period on the time resolution below. To calculate the standard deviation, the stddev() function from postgresql is used. The standard deviation value tells us how much the traffic vary on the time resolution below. In example for week data, the standard deviation tells us how much total traffic for each day, in average vary from a day to the next, within the time period.
Octets - Variance Coeffesient: Variance coeffesient is standard deviation normalized over average traffic. This is calculated by dividing standard deviation on the total octets average for the time resolution below. To compare the burstiness of entries in a report, the variance coeffesient is very convenient.
Packets per second: This shows the traffic measured in packets per second. The value is the average over the time period selected. The value is computed by dividing the total amount of packets in the time period on the number of seconds in the period.
When the data source is sampled, the measured data is divided on the sample rate. In example a sample rate of one-out-of 100, and a measured data of 1000 packets per second, would result in an computed value of 100000 packets per second. In contrast to the estimated octets values from sampled data, the number of packets is fully accurate, because the router selects exactly one-out-of in example 100 packets. If the packet size distribution have been well-known, the octets average could be computed exactly, but obviously the packet size distribution may vary.
Packets - Total: This shows the total number of packets measured for the selected time period.
When the data source is sampled, the measured data is divided on the sample rate. In example a sample rate of one-out-of, and a measured data of 1000 packets, would result in an computed value of 100000 packets. In contrast to the estimated octets values from sampled data, the number of packets is fully accurate.
Packets - Percent: This shows how many packets were measured for each specific entry divided on the total number of packets. The data is presented as percent values.
In example in the IP Protocol report, the TCP row entry shows how many packets was measured as TCP traffic related to the total number of packets.
When the data source is sampled, the percent values are still accurate, since both total and average values are.
Packets per second - Minimum: As explained in the User Guide, data is aggregated from the time resolution below. So data for the day resolution is aggregated from hour. Minimum value means the one of the average packets per second found on the time resolution below, with the lowest value. So when data is to be aggregated for day resolution, the one of the 24 hour-resolution number of packets values is selected. On week resolution, minimum packets per second means average packets per second the day with the least total number of packets.
In example for month January, data is aggregated from week 1, 2, 3 and 4. Packets per second, for these weeks respectively is 4738, 7152, 1889 and 7192. The minimum packets per second value for January is then 1889 packets per second. The minimum packets per second for week 3 is lower than 1889, assumed that the packet rate is not uniformly distributed among the days within that week. If the average packets per second traffic for week 3 vary from 1489 to 10023, then the minimum packets per second for week 3 is 1489.
Packets per second - Maximum: Octets - Maximum is equal to minimum, expect that maximum values are used instead of minimum values.
Packets - Standard Deviation:
Standard deviation is calculated from the total number of packets
from all the time periods contained in the same period on the time
resolution below. To calculate the standard deviation, the stddev()
function from postgresql is used. The standard deviation value tells
us how much the packet traffic vary on the time resolution below. In
example for week data, the standard deviation tells us how much
total number of packets for each day, in average vary from a day to
the next, within the time period.
Packets - Variance Coeffesient: Variance coeffesient is packet standard deviation normalized over average packet traffic. This is calculated by dividing standard deviation on the total number of packets for the time resolution below. To compare the burstiness of entries in a report, the variance coeffesient is very convenient.
Flows per second: This shows the traffic measured in flows per second. The value is the average over the time period selected. The value is computed by dividing the total amount of flows in the time period on the number of seconds in the period.
When the source is sampled netflow, the data is not multiplied in contrast to packets and octets. Thus for sampled data the number of flows is not an estimation of the real value, but rather the measured number of flows it self. Estimating number of flows from sampled data would be a complex operation, and requires to presume the distribution of packets or octets per flow. Since such a distribution is not likely to be equal for all reports, the estimation would result in considerable inaccuracy. However the measured data, even if based on sampled netflow, would be very convenient for analysing trends in the number of flows throughout time, and related to other entries in the report.
Flows - Total: This shows the total number of flows measured for the selected time period.
Flows - Percent: This shows how many flows were measured for each specific entry divided on the total number of flows. The data is presented as percent values.
In example in the IP Protocol report, the TCP row entry shows how many flows was measured as TCP traffic related to the total number of flows.
When the data source is sampled, both the total numbers of flows, and the number of flows for the specific entry might be inaccurate. Obviously the percent value inherit the inaccuracy.
Flows per second - Minimum: As explained in the User Guide, data is aggregated from the time resolution below. So data for the day resolution is aggregated from hour. Minimum value means the one of the average flows per second found on the time resolution below, with the lowest value. So when data is to be aggregated for day resolution, the one of the 24 hour-resolution number of flows values is selected. On week resolution, minimum packets per second means average packets per second the day with the least total number of flows.
In example for month January, data is aggregated from week 1, 2, 3 and 4. Flows per second, for these weeks respectively is 4738, 7152, 1889 and 7192. The minimum flows per second value for January is then 1889 flows per second. The minimum flows per second for week 3 is lower than 1889, assumed that the flow rate is not uniformly distributed among the days within that week. If the average flows per second traffic for week 3 vary from 1489 to 10023, then the minimum flows per second for week 3 is 1489.
Flows per second - Maximum: Octets - Maximum is equal to minimum, expect that maximum values are used instead of minimum values.
Flows - Standard Deviation: Standard
deviation is calculated from the total number of flows from all the
time periods contained in the same period on the time resolution
below. To calculate the standard deviation, the stddev()
function from postgresql is used. The standard deviation value tells
us how much the flow traffic vary on the time resolution below. In
example for week data, the standard deviation tells us how much
total number of flows for each day, in average vary from a day to
the next, within the time period.
Flows - Variance Coeffesient: Variance coeffesient is flow standard deviation normalized over average flow traffic. This is calculated by dividing standard deviation on the total number of flows for the time resolution below. To compare the burstiness of entries in a report, the variance coeffesient is very convenient.
Packet size (bits): The packet size is computed by dividing the total number of packets from the time period and divide on the total traffic (octets).
When data is sampled, packet size will inherit inaccuracy from the octets estimation, although the number of packets is accurate.
The summary report is somewhat special, and contain other types of statistics than the other. Here are short description of the types of statistics available in the Summary Report:
Total Traffic
Total flows: This shows the total number of flows in the time period.
When the source is sampled netflow, the data is not multiplied in contrast to packets and octets. Thus for sampled data the number of flows is not an estimation of the real value, but rather the measured number of flows it self.
Total octets: This shows the estimated total octets in the time period. The traffic is measured by the size of the whole IP packets, including both headers and payload.
When the source is sampled, octets is estimated by division on the sample rate.
Total packets: This shows the total number of packets in the time period selected. This data is still accurate, if the data is sampled.
Data Duration
Total Time This shows the cumulation of the time of each flow added together. This value will be the duration of all flows run in serial. Actually a lot of flows are active simultaneously in the router, so this total value would normally be much greater than the actual time period.
When the data is sampled, this value would be based on the measured number flows, which is much lower than the actual value, because not all flows are discovered.
Flow Duration This shows the duration from which the duration of the period from the start of the first flow represented in the period, until the end of the last flow.
The reason why the data duration is slightly different from the selected time period, is that netflow data for a flow is not exported from the router before the end of the flow. Therefore, a flow which span over the border from the previous to the current time period, will be included in the report. This flow have a start time stamp before the start of the period.
Real Duration This shows the duration from the export time of the first flow in the period to the export time of the last flow in the period. This value will normally be much similar to the exact time period for which the data is collected or aggregated. In cases with small amount of data, there might be a significant delay from the start of the time period to the export of the first flow, which will cause the real duration to be less than the time period.
The fact that flow data from a previous time period can be included in the statistics for this time period, will obviously cause some inaccuracy related to the real traffic for that period. However, there will not be a general over- or underestimation of the flow data, because on average an equal number of flows will be lost on the end of the time period, as the one extra at the beginning of the period.
Flow Averages
Average Flow Time: The average flow time is an average over the flow time for each of the measured flows.
When sampling is enabled, flow start and end are
not as accurate as if not. The reason is that SYN and
FIN packets may not be discovered, and in periods of
the flow with small amount of traffic, the flow could be wrongly
estimated to be ended, and when the flow is discovered again it
will count as a new flow.
Average Flow Size [bits]: This shows the average size of the flows, from the measured octets divided on the number of flows.
When data is sampled, the octets value is multiplied to compensate for the sampling, while the number of flows is not. This means that the average flow size will be higher than the real value.
Average Packets per Flow: This shows how many packets a flow contains on average. The value is computed by dividing the number of packets divided on the number of flows.
When data is sampled, the octets value is multiplied to compensate for the sampling, while the number of flows is not. This means that the average packet size will be higher than the real value.
Average Octets per second per Flow [bits per second]: This shows the average bit rate for each individual stream. The value is calculated from total octets divided on total time.
When data is sampled, not all flows are discovered, and consequently the total time will be much lower than the real value. This will cause the average octets per second per flow to be higher than the real value.
Average Packet Size: This shows the average size of a packet, which is computed from estimated number of octets divided on number of packets. The average packet size is the IP Packet size including both headers and payload.
Averages based on data duration and real duration
When computing averages some value is divided on the time period for which the data is measured. We have three different time period measurement, for which generates slightly different averages. First we have the Stager time period which is predefined time periods, which could be an hour, a day, a week, etc. This will generate the most correct averages.
In addition averages could be based on data duration, which is measured values divided on the time duration from the start of the first flow, to the end of the last flow. These averages will tend to be somewhat lower than the real values, because at the end of the time period, some data is not collected due to flow export delays. Some flows are current before the end of the time period, but because they span the time period limit, they will not be included before the next period. The same, but opposite effect will apply at the start of the time period. Averages based on data duration do not support aggregation, so on all time resolutions but the lowest, these values will be zero.
Averages based on real duration, is values divided on the time duration from the export of the first flow to the export of the last flow. These averages would tend to be somewhat higher than the actual value, because the real duration is often some shorter than the full time period for which data is collected.
Flows per Second This shows the average number of flows measured to stop per second.
When data is sampled, the number of flows per second is somewhat lower than the actual value, because not all flows are discovered.
Octets - bits per Second This shows the average bit rate of data in the measured time period.
Packets per Second This shows the average number of packets measured per second.
Concurrent Flows This shows the average number of concurrent flows. The value is computed by dividing the total time on the time period duration.
The higher sample rate the more accurate the estimation would be. Random sampled data is more accurate than sampled data. Random sampling means that the average length between each packets is randomly selected. If normal sampling is used pattern in the Internet traffic will produce additional inaccuracy. To fully avoid this inaccuracy time between sampled should be a negative exponential distributed stochastical variable, with the mean equal one over the sampling rate.
SI units are used for denomination; kilo, mega, giga, tera, etc. This is used in all situation where bits are measured. To specify that SI units are used, we use the denominators; k=kilo, M=mega, G=giga, T=tera, etc. SI units mean that 1kbit = 1000bit, 1Mbit = 1000kbit, etc. The defined SI units are as follows:
|
Denom. Abbrev. |
Denominator |
Value |
|---|---|---|
|
k |
Kilo |
103 |
|
M |
Mega |
106 |
|
G |
Giga |
109 |
|
T |
Tera |
1012 |
|
P |
Peta |
1015 |
|
E |
Exa |
1018 |
Stager allows custom reports to include binary denominators for data types. To not interfere with the SI units, we use the IEC recommendation for binary unit denominators. We strongly advise Stager administrators not to use binary denominators in bit context. Binary denominators if used, should only be used in byte context, related to storage and not transmission. The defined binary denominators are as follows:
|
Denom. Abbrev. |
Denominator |
Value |
|---|---|---|
|
Ki |
kibi (Kilobinary) |
210 |
|
Mi |
mebi (Megabinary) |
220 |
|
Gi |
gibi (Gigabinary) |
230 |
|
Ti |
tebi (Terabinary) |
240 |
|
Pi |
pebi (Petabinary) |
250 |
|
Ei |
exbi (Exabinary) |
260 |
To create a plot, you should first select a report which is plottable (most are). Then checkboxes are places for each row, and for each plottable data column. Select the rows you want to include in the report, and data columns to plot for each row, as visualized in Figure 3.2, “Selecting rows and columns to setup a graph.”. You then need to decide which type of plot you want. There are four types; area, line, pie chart and 3D pie chart. The line and area graphs are not available from the highest time resolution, since plots needs data from at least one time resolution higher. When you are ready click the Plot Graph button to proceed. After a few seconds, you will be presented with the plot shown in Figure 3.3, “Example of a plotted graph.”.
Figure 3.2. Selecting rows and columns to setup a graph.
![]()
Notice that there is a shortcut time navigation by clicking on the right or left side of the plot image. You will then be redirected to the next or previous time period. Likewise you can click in the middle of the graph, to zoom into that specific time period. If you are on the next to the highest time resolution, zooming in will change graph type to pie chart.
Figure 3.3. Example of a plotted graph.
![]()
Due to a problem with indexes in the Postgresql database, plotting from some reports might timeout. The actual reports, is those with potentially a large amount of rows, including:
Transport Layer Port report
Source and Destination IP reports
Source and Destination AS reports
The
reason is that selecting multiple rows, result in a OR-clause.
Unfortunatly OR-clauses cause the port-number index not
to be used. The result is a very slow query, even with a medium/small
database.
Postgresql
version
8.0, which currently is released as beta annouce support of
OR-clauses together with indexes. Here is a quote from
their 8.0 release note:
Improved index usage with OR clauses (Tom) This allows the optimizer
to use indexes in statements with many OR clauses that would not have
been indexed in the past. It can also use multi-column indexes where
the first column is specified and the second column is part of an OR
clause.
To avoid the timeout problems plot only one port, IP or AS at the time. Optionally you might want to use the Postgresql version 8.0 beta. Another approach is to configure the Stager-backend to trunctate the number of rows store in the database foreach observation point for each time period. This will improve performance on theese reports, but of course will result in no available data for the least used ports, IP's and AS'es.
There is an option in the user.config.php
configuration file (see note Configuration
options in user.config.php), whether the complete
session object should be passed by every link or whether is should be
stored on server, and identified by a session cookie.
user.config.phpSystem
administrators might note that the $config['session']
parameter in user.config.php decides whether session
objects or long URL-s is used in the frontend. true
means that session information is store server-side, and short URL
will be used.
When long URLs are used, you can save the URL as a bookmark in your browser, and that bookmark will later send you to the exact same report. Additional you can send the URL to a friend, and he will get the same report (if the user is authorized to view the specific report).
If short URLs are used you can not copy and send the URL. And if the URL is long, it will not be convenient to send, in example because of line wrapping in your e-mail client. Therefore Stager supports report aliases. A report alias is a very short URL which point to a specific report, and the report aliases is stored server-side, in the database. The creation of a report alias is user initiated. By clicking on the create report alias link at the lower right of the page, you will be told the URL. If your Stager is set up to use short URLs, you can use the report alias to store bookmarks in your browser. Just save the report alias URL as an bookmark.
Note that the web server might be set up to purge report aliases which is not used in some time. If it is very important for you to that report aliases are not deleted, talk to the system administrator.
Table of Contents
The pages is written in standardized XHTML 1.0 language. A browser that support CSS is recomended, but not required.
On the PC platform; Internet Explorer have some problems with transparent PNG images which makes the pages not so pretty. In addition is lack support of some important CSS features. On the PC platform; Opera and Mozilla (or Firefox) is well-tested and recomended.
On the Mac platform; Internet Explorer 5.2 has some issues which makes Stager unstable. Safari, Mozilla (or Firefox, or Camino) and Opera is recommended and well-tested.
On the Linux platform; Mozilla (or Firefox), Opera and Konquerior is recomended and well-tested.
Stager is tested on NetPositive for BeOS to perform well, an old browser which lack CSS support.
Stager has specialised support for printing, by a specialised printing style sheet which will be enabled automaticly when printing. This should work out-of-the-box, by printing as you normally do.
In Opera, you can easily preview the how the printed report will be appear by pressing the P shortcut.
The URL uniquely represent a report, so you can copy the URL on a report, pass it to your friend by e-mail, and he will be able to see the same report. However, he will not if the report is access restricted (by IP-address or user name and password).
Using the accesskey="KEY"
feature of XHTML, almost all form elements are available from
keyboard shortcuts.
In Opera keyboard shortcut's are available with Shift-Escape-KEY.
Below is a list of the keyboard shortcuts in Stager:
|
Accesskey |
Description |
|---|---|
|
b |
Select Database |
|
t |
Select Table/Graph |
|
r |
Select which report |
|
a |
Select advance or simple feature set |
|
s |
Select type of statistics |
|
l |
Select row limit |
|
z |
Zoom into time period |
|
h |
Single time period |
|
j |
Multiple time periods |
|
k |
Decreasing time periods |
|
g |
Select observation point group |
|
d |
Select device |
|
o |
Select observation point |
|
n |
Select single observation point |
|
m |
Select multiple observation points |
|
c |
Select collection of observation points |
|
i |
Select in traffic |
|
u |
Select out traffic |
|
e |
Enter user name |
|
p |
Enter password |
On newer Mozilla based browser prefetching is automaticly enabled. This is a feature which when you enter a report, automaticly loads the next and previous time period into cache, so navigation in time will be a very responsive user interaction.