: Unknown Applications by Destination Address
Focus
Focus

Unknown Applications by Destination Address

Table of Contents

Unknown Applications by Destination Address

Collects information from traffic logs that involve TCP or UDP traffic, but the application cannot be identified. The traffic's destination IP, as well as the number of total bytes in the session are collected. Only traffic logs written as the result of the end of a network session are used.

Metric Details

Category
Threat Prevention
This metric can be used for threat research.
Can identify a network.
Once a week
Introduced
Content version 8284
Telemetry Tier
Full
Equivalent CLI Command
pan_report_gen -t trsum -n 20 -ac dst -vc count,bytes -s count -c 'Unknown Applications by Destination Addressess' - q 'subtype eq end and (app eq unknown-tcp or app eq unknown-udp)' -p last-24-hrs