Terminology Index

Glossary

1801 terms

Open concept maps

Showing 1089-1120 of 1801 terms

N
17

Network Telemetry

The data network devices and tools produce, flow records, packet captures, DNS, proxy, firewall, and IDS logs, that defenders collect for detection, hunting, and investigation. The lifeblood of network monitoring.

Network telemetry is the broad set of observations from network infrastructure: who connected to whom, what protocols and how much, what DNS resolved, what proxies allowed, what firewalls dropped, what IDS flagged. Centralized and queried, it powers detection of network-based attacks (C2, exfiltration, scanning), hunting, and incident investigation. Its completeness and quality, alongside endpoint and identity telemetry, define how much of the network attack surface defenders can actually see.

Introduced in: Logging, Monitoring, and Telemetry

Examples

  • Collecting flow, DNS, and proxy logs as network telemetry.
  • Using telemetry to investigate a host's outbound connections.
  • Building network detections on top of centralized telemetry.

No related terms linked yet.

O
15