Application Intelligence Field References
The following table lists all the fields utilized while configuring an Application Intelligence, Application Filtering Intelligence and Application Metadata Intelligence sessions.
Application Intelligence Session
|
Field |
Description |
|---|---|
|
Name |
Enter a unique name for the Application Intelligence session. |
|
Description |
(Optional) Enter a description for the session. |
|
Environment |
Select Physical to configure the session for GigaVUE HC Series devices. |
|
Node |
Select the node on which you want to deploy the session. |
|
Monitoring |
Enables or disables Application Visualization (AppViz) for this session. Monitoring is enabled by default and can be disabled when not required to improve performance. |
|
Export Interval |
Displays the interval at which AppViz statistics are exported to GigaVUE-FM. The value is fixed at 300 seconds (5 minutes) and is not user-configurable from version 6.4 onwards. |
|
Fast Mode |
When enabled, uses light parsers to increase DPI performance for HTTP and DNS. Only a limited set of HTTP attributes is supported and GigaVUE-FM automatically exposes only the supported attributes. Fast mode can be enabled or disabled only when creating a new session. |
|
GigaSMART Group |
Select an existing GigaSMART group, or create a new group by specifying an Alias and selecting one or more engine ports in the Port List. |
|
Application Session Filtering Buffer Size |
Configures the buffer size used by Application Session Filtering in the GigaSMART group. |
|
Metadata Export Buffer Size |
Configures the buffer size used for exporting metadata in the GigaSMART group. |
|
User Defined Applications |
Associates a User Defined Applications profile with the session so that the DPI engine can classify proprietary or internal applications based on user-defined signatures. |
|
IP Interface Type |
Select IPv4 or IPv6 as the IP version for the AppViz export interface. |
|
IP Address / IP Mask / Gateway / MTU |
Configure the IP interface used to export application statistics. The destination IP address must use the same IP version as the selected interface. |
|
Destination IP Address |
Specifies the IP address of GigaVUE-FM (or other collector) that receives AppViz statistics. By default, the GigaVUE-FM management IP is displayed. |
|
Source Ports |
Select one or more network ports or port groups that provide the traffic to be monitored by the session. Ports already used as sources in intent-based orchestrated solutions are not listed. |
|
L2–L4 Rules |
Defines Layer 2–Layer 4 conditions for each Source Traffic block. For each rule, click Select Conditions, choose a qualifier (such as IP version, IP source/destination, VLAN, protocol, or port), set the value, and select Pass or Drop and Bidirectional or unidirectional. |
|
+ (Add a Rule) |
Adds another L2–L4 rule to the current Source Traffic block. |
|
+ New Source Traffic |
Adds another Source Traffic entry with its own source ports and L2–L4 rules. |
Application Filtering Intelligence (AFI)
Application selection and destination traffic
|
Field |
Description |
|---|---|
|
Selected Applications |
Lists the applications chosen from Total Applications on the Application Intelligence dashboard for creating an AFI policy. You can select one or more applications. |
|
Pass |
Marks the selected application to be passed to the tool ports configured in the associated Destination Traffic Priority block. |
|
Drop |
Marks the selected application to be dropped at the tool ports configured in the associated Destination Traffic Priority block. |
|
Destination Traffic Priority |
Represents a second-level AFI map that forwards filtered traffic to tool ports. You can configure up to five Destination Traffic Priorities per AFI solution and reorder them to change priority. |
|
Tool Ports (Select ports …) |
Select the tool ports or tool port groups that receive traffic for this Destination Traffic Priority. If the required port is not visible, use Port Editor to mark it as a Tool port. |
|
Port Editor |
Opens an inline editor to change the Type of a physical port to Tool, after which it appears in the tool port selection list. |
|
Pass All |
When enabled for a Destination Traffic Priority, passes all applications that do not match any explicit AFI rules in that priority. No-rule-match traffic can be monitored using map rule counters. |
|
Advanced Rules |
Opens the advanced rule configuration for the selected Destination Traffic Priority, allowing you to define non-application criteria (for example IP, VLAN, DSCP, pattern match) that must be met before traffic is passed or dropped. |
|
+ Add New (Destination Traffic Priority) |
Adds another Destination Traffic Priority (second-level map). A maximum of five priorities can be configured per AFI instance. |
|
Filter to |
Applies the AFI configuration and binds selected applications and rules to the Destination Traffic Priority. |
AFI Settings
|
Field |
Description |
|---|---|
|
Bidirectional |
Configures whether AFI maintains flow state and applies rules to both directions of a session. When disabled, each direction is treated independently. Enabled by default. |
|
Timeout |
Configures the idle timeout for AFI sessions. The default is 15 seconds; the valid range is 10–120 seconds. Flows that remain silent beyond this interval are flushed. |
|
Buffer |
Configures the number of initial packets that AFI buffers before applying filtering rules. The default is 20; the valid range is 3–20. Lower values may cause drops if more packets are needed for DPI classification. |
|
Protocol |
Selects the transport protocols for which AFI maintains sessions. Options include TCP only, UDP only, TCP-UDP, TCP UDP and SCTP, and SCTP only. Traffic that does not match the selected protocol set is dropped unless explicitly handled elsewhere. |
|
Session Slicing |
When enabled, allows you to mention the Packet Count. The Packet Count limits the number of packets passed per flow to a configurable value in the range 2–100. Useful when tools only need the first few packets, such as TLS handshakes. |
|
Session Fields |
Configures the protocol fields used to uniquely identify flows. The default 5tuple uses inner source and destination IP addresses, source and destination ports, and protocol; VLAN can optionally be included. |
AFI Advanced Rules
|
Field |
Description |
|---|---|
|
Select Options |
For each advanced rule, select a qualifier from the drop-down list, such as DSCP, ERSPAN ID, EtherType, GRE Key, GTP-U TEID, IP Fragmentation, IP Version, IPv4 Source/Destination, IPv6 Source/Destination, MAC Source/Destination, MPLS Label, Port Source/Destination, TCP Control, VLAN, VN-Tag VIF IDs, VXLAN ID, or Pattern Match. |
|
Pattern Match Type |
When Pattern Match is selected, choose String or Regex and provide the search pattern to match data in the packet payload. |
|
Value |
Enter the value appropriate for the selected qualifier (for example VLAN ID, IP address, DSCP number, or string/regular expression pattern). |
|
Pass / Drop |
Specifies whether packets matching this advanced rule are passed to the destination or dropped. |
Application Metadata Intelligence (AMI)
Application and attribute selection
|
Field |
Description |
|---|---|
|
Selected Applications |
Lists the applications chosen from Total Applications on the Application Intelligence dashboard for exporting metadata. |
|
Attributes |
For each selected application, enables you to select the attributes to be exported. Each exporter can export metadata for up to 256 applications, and up to 64 attributes per application. |
|
Export / Export To |
Marks the selected applications for export and associates them with the configured exporters. |
Destination Traffic – Exporters
|
Field |
Description |
|---|---|
|
Tool Name |
Configures an alias for the metadata collector (for example Splunk, NDR-1). |
|
IP Interface |
Selects the IP interface on the Gigamon device that connects to the collector. |
|
Tool IP Address |
Specifies the IP address of the tool that receives exported records. |
|
Template |
Selects a pre-defined tool template that defines applications, attributes, and export format, such as SplunkMetadataTemplate, SecurityPosture, RogueActivity, or UnmanagedAssets. |
|
L4 Source Port |
Specifies the source UDP port used by the exporter. |
|
L4 Destination Port |
Specifies the UDP destination port on the collector. When the export format is CEF, the default is 514; when the format is NetFlow, the default is 2055. |
|
SNMP |
Enables or disables processing of SNMP packets (UDP 161) on the exporter interface. All exporters sharing an IP interface must have SNMP configured consistently. |
|
Application ID |
When enabled, exports the Application Name for all applications identified by the DPI engine. Requires AMI/SVP/ZTA license. |
|
Application List |
Limits application metadata export to the selected applications or protocols on this exporter. Packet attributes (Collects) are still exported for all applications unless traffic is filtered using AFI or flow maps. |
|
Format |
Selects the export format: NetFlow or CEF. |
|
Version |
For NetFlow format, selects the NetFlow/IPFIX version: v5, v9, or IPFIX (IPFIX is the default). |
|
Template Refresh Interval |
Configures how often template records are exported for IPFIX. The default is 60 seconds; the valid range is 1–216000 seconds. |
|
Record Type |
Selects how network and application metadata are exported. Segregated exports separate records for network and application metadata. Cohesive exports a consolidated record comprising both. The default depends on the configured Flow Behavior (Unidirectional or Bidirectional). |
|
Active Timeout |
Configures the interval for exporting interim records for long-lived flows. The default is 60 seconds; the valid range is 1–604800 seconds. |
|
Inactive Timeout |
Configures the idle timeout for marking flows as inactive and exporting their records. The default is 15 seconds; the valid range is 1–604800 seconds. |
Advanced Settings – Collects
|
Field |
Description |
|---|---|
|
Counter |
Enables export of Bytes and Packets counters and configures the counter width (32- or 64-bit). NetFlow v5 supports only 32-bit counters. |
|
IPv4 Collects |
Enables export of IPv4 attributes such as Source Address, Destination Address, Protocol, DSCP, TOS, TTL, header length, payload length, and fragmentation details. |
|
IPv6 Collects |
Enables export of IPv6 attributes such as Source Address, Destination Address, Next Header, Flow Label, Traffic Class, DSCP, and fragmentation details. |
|
Transport Collects |
Enables export of transport-layer fields such as Source Port, Destination Port, TCP flags, TCP sequence and acknowledgment numbers, MSS, Aggregate Window Size, and Zero Window statistics. |
|
ICMP Collects |
Enables export of ICMP Type and Code for IPv4 and IPv6 ICMP traffic. |
|
Data Link Collects |
Enables export of Source MAC, Destination MAC, and ingress VLAN ID. |
|
Timestamp Collects |
Enables export of System Uptime First, System Uptime Last, Flow Start, and Flow End timestamps. |
|
Flow Collects |
Enables export of the flow end reason (for example TCP FIN, RST, or inactive timeout). |
|
Interface Collects |
Enables export of input and output interface index (2- or 4-byte widths) and input interface name, with configurable name width. Supported for standalone and legacy cluster deployments. |
Application Metadata Settings
|
Field |
Description |
|---|---|
|
Events |
Controls when records are exported for TCP flows. Transaction End exports records as soon as TCP connections terminate; None exports records based only on inactive timeout. |
|
Flow Direction / Behavior |
Selects Unidirectional or Bidirectional flow behavior. In Unidirectional mode, one record is exported per direction. In Bidirectional mode, a single record is exported for both directions of a flow. |
|
Timeout |
Configures the cache timeout for flows maintained in the AMI cache. The default is 300 seconds; the valid range is 1–604800 seconds. |
|
Cache Size |
Sets the maximum number of concurrent flows that can be tracked. Valid ranges depend on platform and generation; from 6.12 onwards, the maximum supported value is used as the default for new configurations. |
|
Multi-Collect |
When enabled, allows multiple values to be exported for attributes that can have more than one value (for example DNS host addresses). IPFIX supports up to five values per attribute; CEF has no limit. |
|
Data Link |
When enabled, exports Source and Destination MAC and VLAN ID and treats flows with identical 5-tuples and different VLAN IDs as the same flow. |
|
Observation Domain ID |
Configures a user-defined identifier in the range 0–255 that, combined with the GS engine slot, forms the 4-byte Observation Domain ID used by collectors to distinguish sessions. |
|
DPI Packet Limit |
Restricts the number of packets per session sent to the DPI engine to improve performance. Recommended values are between 20–50, since the first packets in a flow typically contain the most significant attributes. |
|
Aggregate Mode |
When enabled (Gen3 only), exports minimum, maximum, and mean RTT and TCP loss bytes per export interval for supported protocols such as TCP, HTTP, SSH, TELNET, ICMP, and ICMPv6. |
|
Recurring Attributes |
When enabled, exports TLS Server Name for the lifetime of new TLS flows. When disabled, the value is exported only once at the beginning of a flow. Configurable from the Traffic Policy workflow supported on GigaVUE HC Series Gen3 GigaSMART module. . |
De-duplication
|
Field |
Description |
|---|---|
|
De-duplication |
When enabled for an Application Intelligence solution, inserts the GigaSMART De-duplication operation into the AFI and/or AMI path to remove duplicate packets before they reach the tools. Requires a De-duplication license. |



