I'd like to be able to generate an advanced alert in the form of an Email that looks for the following:
Source Subnet: 10.206.33:0/24
Destination TCP Port: 5745
Destination Network: 10.207.x.x/16.
The intent here is to alert on the inability of a Riverbed to cease flow optimization of Repliweb Traffic. If the Riverbed is working properly, you will not see this flow. However, once it stops optimizing, you will see the flow as it's noted above
Does anyone know of a way to do this with advanced alerts using NTA flow information?
Thanks