View events for elephant flows

This task enables you to monitor elephant flow connection events to track flow detection, bypass, and throttling activities through the Reason field in connection events.

After configuring your elephant flow settings, monitor your connection events to see if any flows are detected, bypassed, or throttled. You can see this information in the Reason field of your connection events. The three types for elephant flow connections are:

  • Elephant Flow

  • Elephant Flow Throttled

  • Elephant Flow Trusted

Procedure


Step 1

Choose Events & Logs > Analysis > Unified Events.

Step 2

On the Events tab, in the search field, type "Reason" and then "Elephant Flow" to search for elephant flow events.

Tip

To see Elephant Flow Trusted or Elephant Flow Throttled events, type "Reason" and then "Elephant Flow Trusted" or "Elephant Flow Throttled", depending on what you want to search.

Step 3

View the elephant flow that was detected mid-flow and the Reason field shows Elephant Flow. At the end of the flow, it was bypassed and the Reason field shows Elephant Flow Trusted.