Stager User Documentation

Sverre Sveum Moen

Preface

To be written.



Chapter 1. The Setup Page

The first page you see is the setup. In the upper left you may provide your user name and password, and log in. At this page you can choose either to create an overview or a specific observation point report. Click the tab of your choice.


Overview Report.


Specific Observation Point Report.

In essence the

The settings of the setup screens are mostly quite intuitive. However, the “Show inactive” check box could need a little explanation. By checking it observation points that have been active earlier, but that are currently inactive will be included in the report as well.

The “Create report” button displays the report in the main Stager page. The setup page is normally only used for the initial report. It would be natural to create the next reports directly from the main Stager page.

At the setup page you are also allowed to perform a full reset of your Stager session. If you are experiencing trouble generating a report this could be the trick. Only your ongoing session with Stager is affected by the reset function.



Chapter 2. Navigation

Table of Contents To be updated!

The report page is divided in two sections. The navigation in top, and the main in which presents the reports as table data or plots. The results of the actions taken in the navigation part are rendered in the main part. In this chapter you will learn how to navigate effectively in Stager.

We start by introducing time navigation. Navigation in time includes traversal back and forth in time periods. Supported time resolutions range from hours to months.

Stager makes it easy to set up reports, even for beginners. This is due to the use of drop down menus. All possible settings appear in these menus. No need to type in anything. The report type, the transformation and the view of the report has to be selected. In addition you will have to select the group of observation points or the specific you want the report for. As all these settings are set you can choose either to show the report or to add it to the current one(s).

Reports can be visualized using graphs. Making rough comparisions far easier. Stager supports both pie charts and line plots (and probably bar plots soon), enabling you to peek at the data of a current point in time, or observe it as it develops over time.

There are filter and sort functionality that ease the task of getting the information you are looking for.

The navigation among reports is taken to the next level by the context menu introduced in release 3 of Stager. A context menu can be called on almost all data elements of a report, giving you several choices related to that element, ranging from general filtering to more specific functionality.



Selecting time period

To navigate in time you must understand the concept and difference of time periods and time resolutions. A default installation of Stager may contain time resolutions including hour, day, week and month. Before moving on let us clearify what resolution is. The highest resolution is the shortest period of time, but is at the lowest level. It can be compared to climbing a ladder. At the bottom level you can see every tiny detail of the ground beneath you. The resolution is high. By going up a few steps, your view will widen. You see more, but at expense of some detail. Hence the resolution is reduced as you are going up. The opposite comes true climbing down the ladder. Lower level, higher resolution.

In the week resolution time period you are shown data for one week at a time. The data for a week is aggregated from the data of seven days. Likewise data for day resolution is aggregated from 24 hours. Some statistics are not available at the lowest level, like min, max, standard deviance and variance coeffesient. Plotting line and area graphs are not possible at the lowest level, because these graph types plot data during a period; an approach in which uses data from the level below.


Time navigation buttons.

To go to a higher level time period, use the arrow pointing upwards. Going to a lower level requires you to select what part of the current time period you want to zoom into. Let us say you are currently in week resolution, then the drop down menu will let you choose among the days of the week.

For traversal back and forth in time, changing the time period, the user can use the single or double arrows in the time navigation bar. Single arrows bring you to the next or previous time period. For example, if you are on Monday, then the next button would take you to Tuesday. A double arrow takes you to the next or previous time period jumping in steps of the time resolution above. If currently on Monday, the double right arrow would move you to the Monday next week.

The calendar displays the last five months, and lets you go directly to a specific date. In hour resolution you are taken to the first hour of the selected date. In week and month resolution you are taken to the week or month of the day, respectively. The calendar is displayed by clicking the calendar icon.


Calendar icon.


Calendar.



Selecting report

Different types of data distribution is available in different reports. The IP protocol report for example shows the distribution of traffic between different IP protocols, like TCP, UDP, ICMP etc. Much data is available for each report. Examples are total octets, average octets, average package size and number of flows per second. It would not be possible to display all information at the same time in a reasonable way. Different transformations show different subsets of data. Transformations are discussed in the next section.

The set of predefined reports available in the default installation includes:

Note: Some of these reports require the user to be logged in..

The report type is choosen from the drop down menu marked below.


Report types.

The different report types will be explained in the next chapter. In addition we will describe the transformations of the reports.



Selecting transformations

A report has one or more transformations. A transformation represents a subset of the available statistics for a report. The summary transformation displays a summary of the report. In the overview transformation several observation points or interfaces are used, making it easy to make comparisions. The table is usually used to present data for a particular observation point. And the global transformation is another sort of overview. The different transformations defined are:

Transformations are selected using the marked drop down menu:


Transformations.



Selecting views

In some reports there are several views available. The standard view presents summary statistics about octets, packets and flows, and is kind of an overview. Many reports offer additional views. These views usually are more specific. Examples are detailed views for octets, packets and flows. What views are available actually depend on what report and transformation that is selected.

Setting the view is done in the marked drop down menu as shown below.


Views.



Setting the number of rows

Sometimes there is no reason to display all rows. This can be constrained by setting a maximum row limit. The row limit is set in the marked drop down menu as shown below.


Row limit.



Selecting observation point

The observation point is selected by the drop down menus on the second line. The first one sets the group of observation points. The next sets the observation point. And the last one sets the direction of the traffic. Not all report types let you select observation point. An overview report for example shows a whole group of observation points.


Setting observation point(s).



Showing the report

As you have made the settings for the report and the observation point, it is time create it. To display it you simply hit the show button. Be aware that if you are currently working with several reports, these will disappear. So, by clicking the show button only one report will be shown. The one just specified.


Show report button.

Read the section “Working with multiple reports” to learn about what is important when there are several reports present at a time.



Using filters

Stager allows you to filter reports. Hitting the scissors icon the filter menu will appear.


Filter icon.


Filter menu.

The filter menu lets you choose the column to filter, the filter operation to perform and the value to filter by. Be aware that values presented in the report often are rounded. The value “1.98k” could in fact be any value between 1975 and 1984. The filtering value must be either an integer or a decimal number. Values cannot be written in short notation as in the report. The value “1.98k” is not valid for filtering. But “1980” or “1980.0” would be perfectly OK. To disable the filters simply select none from the filter operations drop down menu. Only one filter can be used at a time for a report.

Available filter operations are:



Sorting

Sorting reports is carried out by clicking the column titles of the report. Naturally only one column can be sorted at a time. The title background of the sorted column turns darker as an indication. Columns can either be sorted ascending or descending. First time sort of a column is ascending. Clicking the title of the sorted column once more will reverse the sort.






Using graphs

Graphs let you visualize your report. Stager provides two types of graphs. Pie charts and plots. Using graphs makes it much easier to compare values at a point in time, or to see the development of a value over time. Those reports supporting graphs has a setup bar right above the report table. In the rows and columns of these reports there are check boxes to check for inclusion in the graph. Make sure at least one culumn and one row is selected, else there will be no data for the graph. The graph type is selected from the drop down menu. By checking the box “Other” a group representing the sum of all rows not selected will be included in the graph. Hit the “plot graph” button to render the graph.



Setup of graph.


The pie chart uses data from one time period, using the current time resolution. Only the first checked column is included in the pie chart. The data of the selected rows in the selected column is used to draw the pie chart.



Pie chart.


The line plot views the data selection over time. One or more culumns can be used with the line plot. For the line plot to be able to make the plot you cannot be at the highest time resolution. It needs data from the time periods of the time resolution above. Hence the line plot is not available for the hour resolution. Line plots feature embedded links in the the graph. This is useful if you are investigating a graph at low resolution. By clicking a link you are taken to the corresponding higher resolution time period. Let us say you are in day resolution. Then there would be 24 links on the plotted line, each link representing an hour of the day.



Line plot.



Working with multiple reports

In many scenarios it is convenient to view more than one report at a time. Stager lets you easily add more reports. To add a report you simply follow the same procedure as if you were creating a single one. The difference is that you hit the add button instead of the show button. The most recently added report will be at bottom. The origin at top. A report can be either in the form of a table or graph. When adding a report you may set a time difference relative to the origin report. This could for example be useful if you would like to view the same report at different points in time. The drop down menu lets you go back in time periods, or go up to a lower resolution time period. The value sets the number of steps, respectively. For example, if you are in hour resolution and add a report with the drop down menu set to up and with the value 2, then you would get a report for the current week. Two steps up.



Add report button.





Time difference settings.



Clicking the delete icon in the upper right of the report will make it disappear. All reports except the origin one can be deleted.


Showing two reports at the same time.



Bookmarks

Using a bookmark makes it easy to return to the same report at a later time. By bookmarking a report you are returned a unique URL address that takes you directly to the report bookmarked.


Bookmark icon.

Bookmarking frequently shown reports or groups of reports could save you lots of time. Sharing a particular report with colleagues is easily done.



Navigation using context menus

The context menu is a menu that shows up when you right click an element in a report table. The choices of the menu is related to the element clicked. By calling the menu on an observation point in a report for example, a menu of available reports for that current observation point will appear. Calling the menu on an IP address will give a menu with choices regarding that IP. Filtering can also be carried out using this menu. Data fields subject to filtering yield a filter menu where you have the same filtering options as if you where using the filter bar on top. The difference is that you do not have type in the filter value when using the filters on the menu. The filter value is then set the value of the field in which the menu was called.



The context menu in action.


By default the context menu only has support for internal navigation in Stager. However, there is no problem to extend it using custom menus. It may easily be integrated with external systems. One example of usage would be IP addresses. As long as the service can be accessed through a URL with the IP address as parameter it can be used by the context menu. Custom menus are defined in an XML file in the backend.


Note: In order for the context menu to work make sure the “Yahoo! UI Library” is installed. And be aware that not all browsers display the menu by right clicking. Opera for instance require you to hold the CTRL while clicking the left mouse button.



Chapter 3. The Reports

Table of Contents

Report Descriptions
Destination Interface
IP Protocol
IP Type of Service
IP Source Address
IP Destination Address
IP Source - Destination Address
Source AS
Destination AS
Source - Destination AS
Transport Layer Source Port
Transport Layer Destination Port
Summary
Types of statistics
Denomination
Plotting a graph
Report Aliases

We will first describe each available report in the section called “Report Descriptions”, then describe all types of statistics available in the section called “Types of statistics”.

Report Descriptions

This is the list of predefined reports. A local installation of Stager may differ in which reports are available.

Destination Interface

This report shows the distribution of the traffic on the observation point selected, to the other interfaces/observation points on the same device. The internal arrows in the device shown in figure Figure 3.1, “Distribution among Destination Interfaces” try to explain the distribution.

Figure 3.1. Distribution among Destination Interfaces

Distribution among Destination Interfaces

The rows in the report shows traffic for each of the red interfaces/observation points shown on figure Figure 3.1, “Distribution among Destination Interfaces”.

IP Protocol

This report shows the distribution of traffic based on which IP Protocol is used. Examples of IP Protocols are: TCP, UDP, ICMP, GRE and PIM.

This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five most used IP Protocols.

IP Type of Service

This report present the distribution of traffic based on the value of the ToS field in the IP header. The value are presented as an decimal number. Later versions of Stager probably will support displaying the values as hex.

This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five most common values of the ToS field.

IP Source Address

This reports shows the distribution of IP Source Addresses for the selected observation point.

This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five IP Source Addresses with the most traffic measured in octets.

IP Destination Address

This reports shows the distribution of IP Destination Addresses for the selected observation point.

This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five IP Destination Addresses with the most traffic measured in octets.

IP Source - Destination Address

This reports shows the distribution of IP Source Destination Address combinations for the selected observation point. Sorted on the pair of from/to IP address with most traffic.

This report is available in Matrix mode. In matrix mode each row/column represent a source/destination IP. In matrix mode only one type of statistic can be shown at the time. You can show octets, packets or flows.

Source AS

This report shows the distribution of Source Autonomous System for the traffic at the selected observation points.

This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five Source Autonomous System with the most traffic measured in octets.

Destination AS

This report shows the distribution of Destination Autonomous System for the traffic at the selected observation points.

This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five Destination Autonomous System with the most traffic measured in octets.

Source - Destination AS

This reports shows the distribution of Autonomous System Source Destination combinations for the selected observation point. Sorted on the pair of from/to AS with most traffic.

This report is available in Matrix mode. In matrix mode each row/column represent a source/destination AS. In matrix mode only one type of statistic can be shown at the time. You can show octets, packets or flows.

Transport Layer Source Port

This reports shows the distribution of the source TCP/UDP (Transport Layer) ports for the traffic on the selected observation point. Each row in the report represent an source port. If your goal is to have an report of distribution of different services in your network, the destination port report below is better suited to identify such services.

This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five source TCP/UDP port with most traffic.

Transport Layer Destination Port

This reports shows the distribution of the destination TCP/UDP (Transport Layer) ports for the traffic on the selected observation point. Each row in the report represent an destination port. The destination port is mapped to a list of well knowned services. But note that this list is not absolute. Some services use a random port, other use several ports, and some even use a port which is reserved for other services.

This report is available in overview mode, where each row represent an observation point, and traffic is shown for the five destination TCP/UDP ports with most traffic.

Note on Transport Layer Port percent value

The percent value of each transport port is computed from the total amount of traffic. Since not all traffic is TCP/UDP traffic, and therefore have no port accociated with it, the sum of all port percentage will not add up to 100%, but will add up to the percentage of the total traffic which is TCP/UDP, which often is pretty close to 100%.

Summary

While all other reports shows observation point distribution, summary shows total statistics for an observation point, as in example total octets, total flows, flow time and average octets. The fields available in Summary reports are explained in detail in section the section called “Types of statistics”.

Types of statistics

Almost all the reports described in the section called “Report Descriptions” have common types of statistics available, which include:

The summary report is somewhat special, and contain other types of statistics than the other. Here are short description of the types of statistics available in the Summary Report:

Note on inaccuracy due to late exported flow data

General note on sampling

The higher sample rate the more accurate the estimation would be. Random sampled data is more accurate than sampled data. Random sampling means that the average length between each packets is randomly selected. If normal sampling is used pattern in the Internet traffic will produce additional inaccuracy. To fully avoid this inaccuracy time between sampled should be a negative exponential distributed stochastical variable, with the mean equal one over the sampling rate.

Denomination

SI units are used for denomination; kilo, mega, giga, tera, etc. This is used in all situation where bits are measured. To specify that SI units are used, we use the denominators; k=kilo, M=mega, G=giga, T=tera, etc. SI units mean that 1kbit = 1000bit, 1Mbit = 1000kbit, etc. The defined SI units are as follows:

Table 3.1. SI Units

Denom. Abbrev.

Denominator

Value

k

Kilo

103

M

Mega

106

G

Giga

109

T

Tera

1012

P

Peta

1015

E

Exa

1018

Stager allows custom reports to include binary denominators for data types. To not interfere with the SI units, we use the IEC recommendation for binary unit denominators. We strongly advise Stager administrators not to use binary denominators in bit context. Binary denominators if used, should only be used in byte context, related to storage and not transmission. The defined binary denominators are as follows:

Table 3.2. Binary Units

Denom. Abbrev.

Denominator

Value

Ki

kibi (Kilobinary)

210

Mi

mebi (Megabinary)

220

Gi

gibi (Gigabinary)

230

Ti

tebi (Terabinary)

240

Pi

pebi (Petabinary)

250

Ei

exbi (Exabinary)

260

Plotting a graph

To create a plot, you should first select a report which is plottable (most are). Then checkboxes are places for each row, and for each plottable data column. Select the rows you want to include in the report, and data columns to plot for each row, as visualized in Figure 3.2, “Selecting rows and columns to setup a graph.”. You then need to decide which type of plot you want. There are four types; area, line, pie chart and 3D pie chart. The line and area graphs are not available from the highest time resolution, since plots needs data from at least one time resolution higher. When you are ready click the Plot Graph button to proceed. After a few seconds, you will be presented with the plot shown in Figure 3.3, “Example of a plotted graph.”.

Figure 3.2. Selecting rows and columns to setup a graph.

Selecting rows and columns to setup a graph.

Notice that there is a shortcut time navigation by clicking on the right or left side of the plot image. You will then be redirected to the next or previous time period. Likewise you can click in the middle of the graph, to zoom into that specific time period. If you are on the next to the highest time resolution, zooming in will change graph type to pie chart.

Figure 3.3. Example of a plotted graph.

Example of a plotted graph.

Note on Slow Reports - Timeout Problem

Due to a problem with indexes in the Postgresql database, plotting from some reports might timeout. The actual reports, is those with potentially a large amount of rows, including:

The reason is that selecting multiple rows, result in a OR-clause. Unfortunatly OR-clauses cause the port-number index not to be used. The result is a very slow query, even with a medium/small database.

Postgresql version 8.0, which currently is released as beta annouce support of OR-clauses together with indexes. Here is a quote from their 8.0 release note:

Improved index usage with OR clauses (Tom) This allows the optimizer to use indexes in statements with many OR clauses that would not have been indexed in the past. It can also use multi-column indexes where the first column is specified and the second column is part of an OR clause.

To avoid the timeout problems plot only one port, IP or AS at the time. Optionally you might want to use the Postgresql version 8.0 beta. Another approach is to configure the Stager-backend to trunctate the number of rows store in the database foreach observation point for each time period. This will improve performance on theese reports, but of course will result in no available data for the least used ports, IP's and AS'es.

Report Aliases

There is an option in the user.config.php configuration file (see note Configuration options in user.config.php), whether the complete session object should be passed by every link or whether is should be stored on server, and identified by a session cookie.

Configuration options in user.config.php

System administrators might note that the $config['session'] parameter in user.config.php decides whether session objects or long URL-s is used in the frontend. true means that session information is store server-side, and short URL will be used.

When long URLs are used, you can save the URL as a bookmark in your browser, and that bookmark will later send you to the exact same report. Additional you can send the URL to a friend, and he will get the same report (if the user is authorized to view the specific report).

If short URLs are used you can not copy and send the URL. And if the URL is long, it will not be convenient to send, in example because of line wrapping in your e-mail client. Therefore Stager supports report aliases. A report alias is a very short URL which point to a specific report, and the report aliases is stored server-side, in the database. The creation of a report alias is user initiated. By clicking on the create report alias link at the lower right of the page, you will be told the URL. If your Stager is set up to use short URLs, you can use the report alias to store bookmarks in your browser. Just save the report alias URL as an bookmark.

Handling of old report aliases

Note that the web server might be set up to purge report aliases which is not used in some time. If it is very important for you to that report aliases are not deleted, talk to the system administrator.

Chapter 4. Tips and tricks

Table of Contents

Browser support
Printing
Copy and Paste URL
Keyboard access
Prefetching

Browser support

The pages is written in standardized XHTML 1.0 language. A browser that support CSS is recomended, but not required.

On the PC platform; Internet Explorer have some problems with transparent PNG images which makes the pages not so pretty. In addition is lack support of some important CSS features. On the PC platform; Opera and Mozilla (or Firefox) is well-tested and recomended.

On the Mac platform; Internet Explorer 5.2 has some issues which makes Stager unstable. Safari, Mozilla (or Firefox, or Camino) and Opera is recommended and well-tested.

On the Linux platform; Mozilla (or Firefox), Opera and Konquerior is recomended and well-tested.

Stager is tested on NetPositive for BeOS to perform well, an old browser which lack CSS support.

Printing

Stager has specialised support for printing, by a specialised printing style sheet which will be enabled automaticly when printing. This should work out-of-the-box, by printing as you normally do.

Tip

In Opera, you can easily preview the how the printed report will be appear by pressing the P shortcut.

Copy and Paste URL

The URL uniquely represent a report, so you can copy the URL on a report, pass it to your friend by e-mail, and he will be able to see the same report. However, he will not if the report is access restricted (by IP-address or user name and password).

Keyboard access

Using the accesskey="KEY" feature of XHTML, almost all form elements are available from keyboard shortcuts.

In Opera keyboard shortcut's are available with Shift-Escape-KEY.

Below is a list of the keyboard shortcuts in Stager:

Table 4.1. Keyboard shortcuts

Accesskey

Description

b

Select Database

t

Select Table/Graph

r

Select which report

a

Select advance or simple feature set

s

Select type of statistics

l

Select row limit

z

Zoom into time period

h

Single time period

j

Multiple time periods

k

Decreasing time periods

g

Select observation point group

d

Select device

o

Select observation point

n

Select single observation point

m

Select multiple observation points

c

Select collection of observation points

i

Select in traffic

u

Select out traffic

e

Enter user name

p

Enter password

Prefetching

On newer Mozilla based browser prefetching is automaticly enabled. This is a feature which when you enter a report, automaticly loads the next and previous time period into cache, so navigation in time will be a very responsive user interaction.