Version 7.0 released - August 25, 2009
Overview of new features/fixes in Scrutinizer v7.0:
- Several new detailed reports that are unique to Scrutinizer
- Ability to drill in and get the raw flows without any aggregation
- Improved Custom Reports allow you to filter in on exactly the information you need. They can be saved and run again later.
- Ranges of ports, applications and IP addresses (class A subnets)
- ToS or DSCP values
- Autonomous Systems
- TCP Flags
- Multiple interfaces from different routers/switches
- Set thresholds with Flow Analytics
- Permissions can be applied as well
- Etc. etc.
- Provides 24 hours worth of data in Scrutinizer or years of data with Flow Analytics.
- Multiple languages supported (e.g. Korean, Japanese, Russian, Spanish, etc.) and easily localized to other languages.
- Exclude transport layer protocol types per router, interface or even globally across all routers / switches. Useful for excluding VPN traffic which Cisco routers sometimes double export in NetFlow.
- Network maps in flash or Google with clickable links that change color based on utilization.
- Customizable login environment for each account.
- Fast reporting - even with routers sending an enormous amount of flows.
- The best archiving in the industry: all the records, all the flows, all the time. 100% of all flow data capture and archived as configured. Forever is configurable at any granularity level.
- IP Grouping support and subnet trends.
- IPv6 Support
- Flexible NetFlow, NBAR and NSEL (NetFlow Security Event Logs) with access to the NetFlow templates
- Applications defined by combination of ports and IP addresses.
- All reports can be emailed on demand or scheduled for regular time intervals.
- LDAP and active directory support for logins.
- Extensive flexibility for VoIP reports. For example DSCP values as they came in and left the router
- CSV and RSS output of all reports
- DNS resolution on the fly. Constantly with the Flow Analytics module.
Commercial Features
- Central Interface offers a distributed solution that scales to enterprise level networks
- Service Provider Module:
- Set permissions per interface per login
- Set permissions per router/switch per login
- Customizable bandwidth monitoring for invoicing over usage
- Flow Analytics:
- Saves unlimited amounts of past data even raw flows for as long as necessary… Years!
- Algorithms perform Network Behavior Analysis on all flows across all routers / switches
- Top (applications, hosts, flows, countries, domains, etc.) across all routers / switches
- Constantly resolving all IP addresses
- Use saved Scrutinizer Reports to monitor for threshold violations
Scrutinizer, an industry leading tool for network traffic monitoring, specializes in analyzing Cisco NetFlow data and providing IT professionals with comprehensive and easy to read usage reports. The added visibility into network traffic patterns allows administrators to better allocate network resources and plan company internet usage guidelines.
In the latest version of Scrutinizer, improved integration with the Flow Analytics add-on lets Scrutinizer watch for potentially hazardous behavior. This is done by running the collected NetFlow through a series of algorithms that determine if the traffic is following normal behavior patterns. Network hosts exhibiting suspicious or inappropriate behavior can trigger alerts.
Visit Plixer.com for more information on what is new in Scrutinizer version 7.0.0.
Scrutinizer System Requirements:
System requirements can vary depending on specific product implementations. Operating platforms include Windows XP/2003/Vista/2008.
Pricing:
Scrutinizer is a free network traffic analysis product that stores data until midnight of each night. For more commercial features and historical data storage, take a look at Flow Analytics.
The Scrutinizer Flow Analytics add-on module, which includes archived data, starts at $995 for 2 routers and ranges up to $8,995 for unlimited routers.
For more information on Scrutinizer product pricing visit the Plixer Purchase Options page.
Evaluation:
Contact Plixer pre-sales support for an evaluation of Scrutinizer NetFlow & sFlow Analyzer and Scrutinizer Flow Analytics.
Version 6.0.0 released - April 16th 2008
Overview of new features/fixes in Scrutinizer 6.0.0:
- The collector now handles more flows
- Overall performance of product has been improved dramatically
- Fixed issue with DNS lookups resulting in non-ASCII characters
- Tuned MySQL settings to better utilize system resource
- The Alarm interface has been dramatically improved
- Statistics in summary tables have been extended to two decimal places
- Settings -> Known Hosts handles invalid IP addresses better
- Scrutinizer now has MyView! Organize your own special view
- Many gadgets have been created and made available to MyView users
- Settings -> Configuration now has better error checking
- Better visual notifications like abnormal status in the Status tab
- More integration with Denika and Logalot (contact Sales for more info)
- Fixed issue where users could create an SNMP credential without a name
- Scrutinizer can be deployed in a distributed manner (contact Sales for more info)
- Some drop downs in mapping have been ordered for easier reference
- Fixed some minor rendering issues between IE6, IE7, and Firefox
- DNS now resolves both columns on conversation tab
- Fixed issue where users couldn't remove Long/Lat coords for a group
- Custom SNMP descriptions and speeds can now be properly changed
- Added more tools when "Launch External Link to Host" is used
- Many web functions such as update checks are improved
- Some navigation has been updated and added to improve the user's experience
- "No longer sending flow" alarms can now be hidden from view
- A wizard to configure Netflow has been added to Settings -> Manage Devices
- Many screens are now consistent in the method to delete multiple settings
- Default Scrutinizer settings can be restored from Settings -> Configuration
- Dragging and drilling now allows users to confirm times
- Fixed some minor issues in times passed when drilling into data
- CSV is now available in all tabs from the drop down menu beside the tabs
- The Vitals tab has an improved look with more information
- Scrutinizer now detects and notifies users if Flash and Javascript are enabled
- A right mouse click on the graph now zooms out
- Users can now search all routers for IPs and Protocols
- Scrutinizer now trends counters from sFlow
- Add or Remove Programs info now accurately reflects version
- Fixed numerous typos and spelling issues
- Fixed issue where users couldn't change bits, bytes, and packets in application tab
- More conversations can be stored in 5m, 30m, 2h, 12h, 1d, and 1w intervals
- The host tab can be properly viewed coming from the AS tab with BOTH selected
- Custom reports settings are now used when previewing reports before saving
- Printing custom reports no longer forgets navigational settings
- Added a change log button in the interface when updates are available
- Added more p2p protocol information to known hosts
- User can now specify the default tab when users first log in
- User can optionally exclude certain traffic (like IPSec) via Configuration
- Updated some IP Type descriptions
- The online help can now be searched
- Improved support for Windows Vista. Contact us concerning Windows 2008
Version 5.5 released - September 25th 2007
Overview of new features/fixes in Scrutinizer 5.5:
- added support to run on Windows Vista
- fixed label issue for sFlow multicast interfaces in custom report cfg screen
- fixed issue where deleting & re-adding a device broke connections on the maps
- clicking the back button to get a previously viewed map now works correctly
- fixed issue where monthly reports wouldn't kick off under certain conditions
- the external link has been set to a whois lookup for new installations
- fixed issue where host replacement variable %I behaved differently in menu
- added Top Interfaces to tree menu which filters that device in the status tab
- users can now define conversation rules in custom reporting
- users can create include and exclude rules in custom reporting
- application groups is now its own tab (renamed to Applications)
- renamed Applications Tab to Protocols Tab
- added Autonomous Systems and QoS support
- changed a couple of graph labels so it's easier to understand
- added unique visitor and connections per host at 1 min intervals
- users can now toggle bits/bytes/packet totals on tab views and flog views
- improved the speed in which the initial status tab renders
- optimized the schema to store GPS coordinates
- added new and improved pie charts
- Tab views have the option to view the data in bar graph format
- users can now specify additional information in scheduled email reports
- devices are automatically hidden from the tree menu if no activity in 24 hrs
- fixed issue where device names were inconsistent in status tab and tree menu
- one error pops up in scheduled reports, even if multiple fields are empty
- users can now create folders to organize their custom reports
- users can now delete multiple custom reports at the same time
- interfaces are now clickable in the standard snmp view to view top 10 data
- license key formats have changed. Old keys still work for compatibility
- maintenance information is now available by clicking product key in tree menu
- flow devices set to inactive will be rendered as blue icons in the map
- fixed a labeling issue when drilling into an application graph
- maps now have support for text-block icons
- improved speed of starting services during upgrades and full installs
- fixed alignment issue in 'Status' tab of the Mapping interface
- added integration link to Denika Performance Trender in tree menu
- fixed an issue with trending involving users try to view future data
- improved speeds when doing mass DNS resolves by preventing duplicate attempts
- fixed a bug that caused the wrong month to display in RSS Feed alarms
- deleting a custom report should delete any scheduled report based on it
- fixed issue that caused groups names with an apostrophe to be duplicated
- bits, bytes, or packets can be set as the default measurement
- collector has been improved to manage rolling data instead of relying on cron
- fixed an issue with dropping expired data. It should now drop properly.
Version 5.0.2 released - May 23rd 2007
Overview of new features/fixes in Scrutinizer 5.0.2:
- now forcing users to re-authenticate after updating to avoid version confusion
- fixed an issue with the collector and business license keys
- fixed a rare issue where host avg/s was reporting higher then max
- fixed issue where outbound selection was not remembered when in App Groups
- fixed issue where users couldn't manually kick off scheduled custom reports
- listening ports will yellow alarm when their processing 50 pkts/s instead of 35
- New LED lets users know if devices are not sending NetFlow properly
- fixed an issue where devices show up in ungrouped when they exist in other maps
- added option to only include PDF attachments in emailed reports
- fixed issue where IP & PROT conversations weren't showing in detail view for a host
- better error message when a "bind" failure occurred when starting the collector
- fixed issue when deleting expired history where data is store on a different drive
- fixed issue where the screen remains blank when looking at one 1 minute datapoint
- fixed graph rendering issue when clicking 7/31/365 after performing a quick search
- fixed labeling issue with GPS coordinates
Version 5.0.1 released - April 12th 2007
Overview of new features/fixes in Scrutinizer 5.0.1:
- inbound (green) on rrd style graphs are now filled in instead of a line
- fixed issue where collector didn't update SNMP information
- fixed mouse over issue on black links
- fixed issue with filtering for protocols with both TCP or UDP defined
- if a router name is not defined, filter now reflects the listening port
- fixed issue where % of utilization was being calculated for sFlow
- fixed issue on status page for utilizations reporting under .001%
- added additional checks and balance in collector for high volume netflow
- fixed minor issues with scrut-rss.exe
- fixed case-sensitivity issue with google api in scrutinizer
- fixed firefox rendering issue on status pop ups from devices on map
- added link to change max number of interfaces when violated in custom reports
- fixed issue with SNMP where ifIndex instances didn't align with ifSpeed
- fixed issue where users see blank graphs when using the GO button
Version 5.0 released - April 2nd 2007
Overview of new features/fixes in Scrutinizer 5.0:
- Removed address and protocol tables in favour of one set of conversation tables
- Reduced the amount of disk space needed to individual conversations
- 1 minute intervals data now stored for a predefined period of time
- Summarized data stored in 5 min, 30 min, 2 hr, 12 hr, 1 day, and 1 week intervals
- Users can define how long to store all intervals of data
- New alarms are created when a device or interface stops sending netflow
- Drag and drill is now possible on weekly, monthly, and yearly graphs
- Greatly improved front-end performance
- The collector can handle more flows
- The ability to send PDF reports
- A new filer service has been added to aid the collector in various tasks
- Scrutinizer now uses MySQL 5.0.27 and requires MySQL 5.0 as a minimum
- Fixed a few spelling typos
- Fixed issue with language file changes not taking effect in the interface
- Fixed an issue with dragging and drilling where times selected slightly shifted
- The ability to create detailed network maps and customize them using a browser
- Improved Google Map integration to include network maps and misc icons
- Global threshold can be defined for utilization. When violated, an alarm is triggered
- Users can configure RSS feeds to include network status and current conditions
- Some previous restrictions on custom reports have been lifted
- All alarms can be sent to a specified syslog server
- The status page can display based on avg of utilization (e.g. 1 min, 30 min)
- Saved the existing manual in PDF format
- Defaults can be set for src/dst, in/out, and top conv/host/app in custom reports
- Improved navigation of product in a lot of areas
- Flogging has been revamped to always be available to any host or protocol
- SNMP real-time is available if a community string is defined
- Alarm condition policies are now configured to allow you to specify a Device
- SNMP query and time out improvements
- 3rd party integration improvements
- The collector can collect from multiple listening ports at the same time.
- Collector now listens on ports 2055, 4739, 9996, 6343 by default.
- New Vitals look. Get statistics per listening port and per flow sending device
- More service/performance indicators on Status Tab
- Ability to set the Status/link Average per minute in the status tab
Version 4.0.1 released - November 16th 2006
Overview of new features/fixes in Scrutinizer 4.0.1:
- fixed issue with some NetFlow v9 configurations with multiple templates
- fixed issue with resolving source and destination address in conversation tab
- changed labeling in CSV file to reflect SRC and DST instead of Rx and Tx
- individual interface RRD files now extend beyond 100% for consistency
- defining an individual protocol is now checked like defining ranges of protocols
- fixed issue with FireFox rendering a blank button in manage NetFlows
- fixed issue where the main screen with tabs would sometimes load within itself
- fixed issue with missing labels in CSV files
- fixed position of logos in tree menu and login form with FireFox browsers
- added decimal places to the status page for more accurate representation
- fixed issue with GRE traffic reporting in Scrutinizer
- fixed a license issue when reverting to Free mode from Enterprise mode
- fixed issue that the collector's output was showing a blank IPFIX conversation
Version 4.0.0 released - October 23rd 2006
Overview of new features/fixes in Scrutinizer 4.0.0:
- added support for Netflow v7, v9, IPFIX
- added support for sFlow v2, v4, v5
- added 95th percentile to Inbound and Outbound trends
- for beta testers, the update icon no longer appears in beta mode
- improved performance when viewing daily/weekly/monthly views
- added the ability to toggle status tab tree menu on and off
- added google maps with GPS coordinates utilities for routers
- added the ability to set a default and display Top X in status tab
- added percentages of utilization in bar graphs on status page
- added "Other" traffic in trends and pie charts
- added the ability to toggle "Other" traffic on and off
- added ability to show "Midnight to Midnight"
- DNS will manage itself. Discovered addresses will reset. Manual ones won't
- added the ability to configure X amount of days for DNS functionality above
- added the ability to add 3rd party hosts and links to the tree menu
- 3rd party links are security based and can be set for each user
- banner ads have been added for the free version. No Ads for licensed version
- improved the searching and filtering functionality
- added trending graphs to conversations with drag/drill technology
- now you can display real-time utilization on individual ports with SNMP
- added 95% percentile to In/Out utilization and SNMP real-time graphs
- some graphs have a new and smoother look to them
- added the ability to show and hide inactive SNMP interfaces in info view
- passwords no longer appear in the URL during Login
- binoculars are no longer available to ISP users
- number of interfaces in custom reports has been increased to 5
- when removing a NetFlow device, the existing alarms are also removed
- refresh count down has been added to the status page
- views can now be scheduled and emailed on a regular basis
- fixed issue in Flogging where you couldn't navigate between views
- removed check all button when not needed in known apps view
- all views now goto trend if you were in trend mode
- police icon no longer opens up a mail message. It opens in another window.
- yellow interfaces in status tab and custom reports appear at the bottom now
- fixed issue with pinch in the first data point on trends in drag and drill views
- fixed issue displaying tabs within tabs in random instances
- syslog: timestamp, router, and interface have been added to alarm descriptions
- fixed issue where you could not define 10 Gb interface speeds
- added percentage column in host/apps/conv tab summaries
Version 3.5.0 released - June 27th 2006
Overview of new features/fixes in Scrutinizer 3.5.0:
- added custom reporting users can now define and display application
- added the ability to navigate to any of the last 30 days in daily view
- added application grouping by defining ranges of ports
- extensive VoIP support with port ranges odd/even (RTP Vs. RTCP) groups
- updated the online help
- added service provider abilities for unique login to specific reports
- Several enhancements on performance
- fixed several bugs
Version 3.1.1 released - April 3rd 2006
Overview of new features/fixes in Scrutinizer 3.1.1:
- added links to show ip for host names in conversations
- fixed issue with returning to all interfaces on a details view
- fixed issue with 7 day and 31 day trends
- fixed issue with drop down not showing custom interface length
- fixed stylesheet issue with firefox browsers
- fixed issue with display details for apps/hosts
Version 3.1 released - March 27th 2006
Overview of new features/fixes in Scrutinizer 3.1:
- can change community string per device in the SNMP summary page
- filtering has been added to the Alarm Conditions Page
- more buttons and icons have been added to streamline navigation
- an issue with the graphs "Pinching" has been resolved
- users can customize a hyperlink that launches their favourite app
- fixed issue with layout when browsers where resized
- fixed issue that caused users to receive emails every 5 minutes
- status of interface is now reflected in the Status Tab
- SNMP Information is accessible from the tree menu
- conversation Details trend graphs are now more detailed
- fixed issue with tabs squishing when browsers were resized
- added the ability to toggle top X from the Top App/Host Tabs
- users can toggle between percent and raw utilization
- fixed issue with inconsistent interface naming
- users can now define/rename hosts from top hosts or detail page
- users can now resolve hosts from any conversation window
- exclusion functionality has been removed to avoid dropping data
- daily/weekly/monthly/yearly data is available for interfaces
- improved interface speed with heavily utilized interfaces
- fixed issue with real time and details view
- fixed issue with SNMP discovery
- fixed issue with filtering for hosts that are destination based
- removed minimum src and dst traffic counter settings
- added icon to host/app tab to display in/out for a year
- fixed issue where protocol types could not exceed 127
- fixed issue with formatting host/app tabs with less then 10 results
- added telnet link in the tree menu
- find utility now uses conversations instead of host/app summaries
- to improve tree menu performance, alarms and flogs have been removed
- fixed javascript error when resizing browser on login screen
- totals are based on total bytes instead of total average of bytes
- fixed saving custom speeds issue when update clicked several times
- The collector no longer alarms on full flog files, improves performance
- fixed issue where sometimes data older then 1 month is retained
- added ability to view up to the top 1000 entries in summary views
Version 3 released - February 15th 2006
Overview of new features in Scrutinizer 3.0:
- Conversations for hosts, host pairs and protocols have been added
- Traffic can be viewed from an inbound or outbound perspective
- Pie charts have been added and can be toggled via the interface
- Daily, weekly, monthly icons are now on the top bar
- Fixed issue with emailing reports with some mail servers
- Added version number to the main Scrutinizer Interface
- Users can click bar graph to view last 5 minutes of data
- Users can define and override SNMP port names and speeds
- The status page is now an HTML page for user's to easily reference
- Improved the overall interface speed and navigation