View events for elephant flows

This task enables you to monitor elephant flow connection events to track flow detection, bypass, and throttling activities through the Reason field in connection events.

After configuring your elephant flow settings, monitor your connection events to see if any flows are detected, bypassed, or throttled. You can see this information in the Reason field of your connection events. The three types for elephant flow connections are:

  • Elephant Flow

  • Elephant Flow Throttled

  • Elephant Flow Trusted

Procedure


Step 1

Choose Events & Logs > + Show more > Connection > Events. You can also view the events from the Unified Events viewer.

Step 2

In the Connection Events page, from the Predefined Search drop-down list, choose Elephant Flows to display elephant flow events.

The diagram illustrates the flow of trusted elephant events, highlighting key components and their interactions within the system.
Tip

To see Elephant Flow Trusted or Elephant Flow Throttled event types, click the Edit Search link on the top-left corner of the page and in the Reason field, choose Elephant Flows in the left panel. Enter Elephant Flow Trusted or Elephant Flow Throttled, depending on what you want to search.

The image illustrates the process of viewing Elephant Flow Trusted and Elephant Flow Throttled event types, highlighting the steps to access the Edit Search link and select the appropriate options in the Reason field.

Step 3

View the elephant flow that was detected mid-flow and the Reason field shows Elephant Flow. At the end of the flow, it was bypassed and the Reason field shows Elephant Flow Trusted.

The image illustrates the monitoring of elephant flow events, highlighting the detection, throttling, and trust status of flows based on the Reason field values in connection events.