Purview Add fingerprint

  • 0
  • 1
  • Problem
  • Updated 1 year ago
  • Not a Problem
we are evaluating Purview, currently we are exporting ip-fix to the appliance while waiting for the nMirror device.

the problem is that when i add fingerprint based in port , it is added as type (General) , and it is never matching , although i already see traffic in this port in the flows , but syill it does not match at all.

any idea?




<Signature name="APP:SEP" protocol="tcp"  group="something" createdDate="2017030100" modifiedDate="2017030103" confidence="10">  <AppID>1600014</AppID>
  <DisplayName value="SEP"/>
  <ExtendedLanguage port="8014"/>
  <Description><![CDATA[]]></Description>
  <Enabled value="yes"/>
</Signature>
Photo of Ahmed Haroun

Ahmed Haroun

  • 888 Points 500 badge 2x thumb

Posted 1 year ago

  • 0
  • 1
Photo of Ahmed Haroun

Ahmed Haroun

  • 888 Points 500 badge 2x thumb
any suggestions?
Photo of Dudley, Jeff

Dudley, Jeff, Employee

  • 914 Points 500 badge 2x thumb
Hi Ahmed,

What sort of device is sending over the IPFIX records to the Purview/Analytics appliance?

Thanks
Jeff