About the Flow Analyzer
The Flow Analyzer detects flow information regarding the endpoints in your environment.
The Flow Analyzer is a component of the Forescout eyeSight (formerly Forescout Platform or CounterAct) Core Extensions Module.
The Flow Analyzer collects a statistical sampling of data about the network traffic in your environment, such as average packet size, average packet rate per second, inbound and outbound bandwidth usage, and DNS resolutions.
Forescout researchers continually attempt to provide better classification and posture assessment services to customers. Customers who opt to allow the anonymous information detected by the Flow Analyzer in their environments to be shared with Forescout provide an important contribution to the Forescout Research and Intelligent Analytics Program. For more information about the program, see the section on The Forescout Research and Intelligent Analytics Program in the Forescout eyeSight Administration Guide.
By default, after you accept the Forescout Research and Intelligent Analytics Program participation terms, your CounterACTdevices share selected endpoint properties with Forescout. The purpose of the Flow Analyzer is to provide additional properties to be shared with Forescout. Properties resolved by the Flow Analyzer are not available to Forescout users from the Policy Manager.
The Forescout Research and Intelligent Analytics Program is a voluntary program. Customers are under no obligation to share their data to help Forescout improve classification. The Forescout Research and Intelligent Analytics Program and the Flow Analyzer provide no immediate benefits to an individual customer. In the long term, the program benefits customers in the form of more precise classification profiles.
How It Works
If additional property creation is enabled in your Flow Analyzer configuration, the following happens:
- Network traffic data statistics are continuously collected and converted to hidden properties. The statistics are collected from two sources:
- Routers and switches that export NetFlow traffic that is analyzed by either the Forescout NetFlow plugin or the Forescout Flow Collector (if installed and configured)
- SPAN traffic, which is converted to NetFlow protocol by the Flow Analyzer
For the complete list of created properties, refer to Appendix I of the Forescout Research and Intelligent Analytics Program Data Security Document.
- If data sharing is enabled:
- All personally identifiable information (PII) is removed from the network traffic data statistics properties. The IP and MAC addresses of endpoints are converted to simulated addresses using a one-way function which ensures that the data can never reveal the actual addresses of endpoints in your network. For more information, see the Forescout Research and Intelligent Analytics Program Data Security Document
- Managed CounterACTAppliances transmit the properties through the Enterprise Manager for upload to the Forescout Research and Intelligent Analytics Program.
Supported Version
This table lists the eyeSight versions that work with the plugin versions covered by this guide.
| Plugin Version | Delivered with Core Extensions Module Version | Works with eyeSight Version |
|---|---|---|
| 1.5 | 1.4.1 | 8.4.1 |
|
1.5 |
1.4 |
8.4 |
|
1.5 |
1.3 |
8.3 |
|
1.4.1 |
1.2.2 |
8.2.2 |
|
1.4.1 |
1.2.1 |
8.2.1 |
|
1.4.1 |
1.2 |
8.2 |
|
1.4.1 |
1.1.4 |
8.1.4 |
|
1.4.1 |
1.1.3 |
8.1.3 |
|
1.4.1 |
1.1.2 |
8.1.2 |
|
1.4.1 |
1.1.1 |
8.1.1 |
|
1.4.1 |
1.1 |
8.1 |
|
1.4 |
1.0 |
8.0.x |
minute read