Top Receivers with the Most Failed Connections report reveals devices that received the highest number of unsuccessful TCP connection attempts, or SYN packets.

Unsuccessful connections (incomplete TCP handshakes) can imply port scanning, penetration testing, and methods used by security testers or hackers to find potential intrusion points on a network. Large numbers of these half-open or incomplete connections can also denote an attempt at a denial of service (DoS) attack.

了解列数据

每个报告的默认视图包含一个有以下列的网格:

  • Receiver. Host name of the top receiver with the most failed connections.
    • 地点。该字段由带有州和国家标识符的组合城市排名组成。
  • City. Top receiver's city.
  • Connection Attempts. Number of failed connection attempts.
  • Packet Rate. Total average packet rate.
  • Packet Percentage. Percentage of top n items ranked.

Several report columns do not appear by default and can be configured to display in this report. You can display the following additional report columns:

  • IP address. Receiver's IP address.
  • Hostname. Receiver's hostname.
  • Subdivision. Subdivision for the current city.
  • Country. Country for the current city.
  • Latitude. Degrees latitude associated with the current city.
  • Longitude. Degrees longitude associated with the current city.
提示: To show reports in full screen with most if not all possible columns, click on report options menu and choose Expand.

Generate a report

Choose source.Choose a networking device or single physical or virtual interface. Choose traffic direction across an interface.

Choose time constraints. Choose times. (Subject to NTA collection interval and retention policies.)Choose, filter, and reorder columns. Choose and hide columns, reorder columns, and apply advanced filters to customize your data view.

Chart, adjust output, and visualize. Apply chart, geo mapping (World Map), and display options in Report Settings dialog (optional).

  • 导出报表数据

    报告数据可以从 WhatsUp Gold 导出、重复使用和以多种格式分发。从“仪表板选项”() 菜单中选择展开 ()。在展开报告后,选择“导出数据”图标以访问以下选项: