January 14, 2025

Root Cause Analysis for Increased Traffic from another Country

Master network insights with Sycope's Trend Dashboards—track traffic, drill into anomalies, and optimize performance effortlessly!

Tracking network traffic changes over time is crucial for optimizing performance and identifying anomalies.

With Sycope’s Trend Dashboards, you gain the power to analyze aggregated streams effortlessly, even over extended time spans. From customizing time frames to drilling down into unexpected traffic spikes, this guide will walk you through the steps to master your network insights. Let’s dive into the details and discover how to make smarter, data-driven decisions for your IT infrastructure.

Trend dashboards allow us to see how the network traffic is changing in a defined time frames. By default, it works on an aggregation streams and therefore is highly performant even with a wider timespan. 

We can access trends by clicking Dashboards from the menu on the left and choosing the desired trends view. In our case it will be Countries Trends.

Trends overview Sycope

Once we are in the desired view, we can start by clicking on the time range and changing the perspective to Last hour.

Time range option

There are a lot of other time options to choose from, including business hours, absolute or relative time ranges. We can also save a custom time range and use it on other views.

Most likely, your country will have the most traffic in the trend charts, which can impact overall analysis. We can hide it by simply unselecting specific traffic in the chart legend.

If we see a peak value for an unexpected country in a timeline widget for Countries by Sent Bytes, we can zoom in inside the chart, which will automatically change the time range that we want to review.

This change will be reflected in all currently viewed widgets.

Countries Bytes sent zoomed in

Using other widgets, for example Countries as Server sorted by Sent Bytes, we can confirm our suspicions and investigate further by right clicking a bar and selecting Drilldown Group Countries and Country Details.

Sycope drilldown country details

 We will be redirected to a dedicated dashboard, which is using a different data stream. By accepting the filter change, Sycope will convert the chosen field and analysis can be continued without interruptions.

Now, we are presented with detailed statistics per Country, including the widget for IPs as Client sorted by Bytes, where Servers are Public and Clients are Private. Thanks to the built-in dashboards and drilldowns, we can easily move between different objects such as IPs, Ports, Countries, Applications and others. In this case we want to continue the analysis by choosing the IP that is responsible for the discovered traffic peak.

We can do that by right clicking this IP and using Drilldown Group Clients and Client IP Details.

Sycope Client IP details drilldown

After finishing the analysis using our Client IP and Country filters, if we remove the second one, we can view the entire traffic for the selected IP. Such filter can be saved and used for other dashboards.

Sycope top servers drilldown

For other situations with unusually high network traffic, we can go through a similar analysis path, using any bar chart and built-in drilldowns to other objects. This deep dive process can include as many steps as we need, in order to find the root cause.

By leveraging Sycope’s Trend Dashboards, you can navigate through complex network data with ease, isolate critical insights, and streamline your analysis process. Whether it’s uncovering traffic anomalies or fine-tuning performance metrics, these tools equip you to take control of your network like never before.

Ready to explore more? Stay tuned for more tips and insights on smarter network management!

Get a monthly dose of blog posts, tips and tricks

Sign-up for the newsletter and be updated about Sycope.

Sign-up for the newsletter
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.