Hello,
I was wondering if it's possible to setup a query in SWQL Studio to look for flows that have a certain number of packets per second. I've looked through Orion.Netflow.Flows (and Orion.Netflow for that matter) but wasn't able to find anything obvious. Essentially what I'm trying to accomplish is if, let's say, IP address x.x.x.x sends 1000 packets per second to internal IP y.y.y.y, trigger an alert. Apologies if this question is too vague but if anyone has ideas on where I can start it'd be greatly appreciated.
Thanks.