Network log analysis using categorical anomaly detection provides insight into communication behaviors between logical hosts by analyzing network connection summary records. The analysis includes metrics such as bandwidth and categorical elements like IP addresses and connection state. The resulting visualization can identify abnormal behavior and can be used for DDoS detection, host communication analysis, and new protocol discovery. thatDot Novelty Detector is a useful tool for enriching telemetry data and enabling real-time anomaly detection.
Sort: