The Anomalous Traffic Detection use case helps you identify sudden spikes in network traffic so that you can detect potential malicious activity. Sudden spikes in traffic can be caused by scheduled backups or virus scanner updates inside your LAN. However, these spikes might also be caused by something different, such as malware outbreaks, rogue FTP servers, peer to peer traffic or hacking attempts. Using the ESM monitoring and investigation tools, you can observe these peaks in network activity and Identify/respond to threats. The Anomalous Traffic Detection use case provides a dashboard for routine monitoring to see what type of abnormal activity is taking place. You can monitor sudden spikes in incoming and outgoing traffic permitted through a firewall, and investigate further to remediate potential threats. ArcSight Connectors supported:
Suggested for you are based on app category, product compatibility, popularity, rating and newness. Some apps may not show based on entitlements. Learn more about entitlements.
Related content and resources
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox