Hi All,
I'm currently looking for software that will act as a SPAN port destination for an interface and interpret captured data, it should be able to do the below;
- Integrate with Active Directory to pull up user/source IP information – This isn’t crucial but it would ideal, getting the source IP address would be fine.
- Must be able to interrogate destination traffic in detail – This is crucial, must be able to provide me with layer 3 and layer 7 detail.
I’ve already got Orion Solarwinds with Netflow and it only gives me the Source/Destination IP address and then I manually have to look up the destination domain which in most cases ends up being one of those hosting companies which doesn’t really help me, I’m looking for something that would tell me that “User/IP address X has been downloading X amount of data from Youtube” or something to that effect.
The more I look at it the more it looks like I need a firewallesque device which I would like to avoid.
Thanks for your suggestions