Hide protocols from display in ACC?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Hide protocols from display in ACC?

L1 Bithead

Does anyone know of a way to hide protocols that would normally display in the ACC? Let's say there is an organization that generates a lot of ICMP traffic. This is all known good so they would like the capability to hide it from displaying in the ACC and Dashboard.

5 REPLIES 5

Cyber Elite
Cyber Elite

you can hide traffic from ACC by creating an accept (or deny) rule with logging ction disabled

T

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L4 Transporter

Some of the ACC information is pulled from dataplane statistics and not traffic logs.  In some cases the only way to suppress protocol data from the ACC is to have a deny rule for that application in the Security policy.  This works well in a Tap mode environment, but may not be what you want to do in an inline deployment.

Cheers,

Kelly

Thank you - we did this, and it works. It is not what we were looking for but will do the job for now.

Thank you - this explains why we are still seeing some traffic but not the levels that we saw before when it was all being logged.

L1 Bithead

All - it seems the best approach to solving this problem at this time is to create a rule for each protocol or application you do not want to display and disable logging and log forwarding. Not perfect, but it works. 

  • 3296 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!