Skip to main content

What We Collect

The following list outlines the specific information sets gathered by the RISC Networks RN150 collecting appliance during an engagement. Data is collected in two distinct phases by the RN150, inventory and performance.

note

For documentation on access requirements please see How We Collect.

Network Equipment

For network equipment, the following information is collected:

TypeCategoryInformation Collected
InventoryHardwareSerial Number Line Cards Flash Size Memory Size Interface Information ENTITY-MIB information
SoftwareSoftware version Flash file list
OperationalRouting Table ARP Table L2 Forwarding Table Neighbor Information (CDP, FDP, LLDP, etc) Spanning Tree Topology SAN Switch Forwarding Information (WWN Names, etc) SCSI Lun Information (FC Switches only) Quality of Service Configuration
PerformanceStatisticalInterface Utilization and Error Statistics CPU and Memory Utilization Statistics Cisco MQC Statistics

Windows Servers

For Windows Servers, the following information is collected:

TypeCategoryInformation Collected
InventoryHardwareSerial Number (Dell Service Tag, etc) Physical Memory Physical CPU Physical Hard Drive HBA Information Network Card information
SoftwareOS Version Installed Applications and versions with process ID information Windows Services and status Logical Disks Windows Shares HTTP get on port 80
OperationalWindows Event Log information (3 days of Errors and Warnings) Citrix Metaframe Server Inventory
PerformanceStatisticalCPU Performance Process specific Performance metrics (CPU, Swap, etc) Memory Performance (bytes used / % used ) Disk (Logical and Physical) performance (I/O per sec, I/O bytes, latency, etc) Windows Network Interface Utilization (I/O bytes, etc) Windows Process Information Windows Netstat Connectivity Information (opt-in only) DNS A records and C names where applicable

Linux/Unix Servers

For Linux/Unix Servers, the following information is collected:

TypeCategoryInformation Collected
Inventory via SNMP and SSHHardwarePhysical Memory Physical CPU Physical Hard Drive Network Interfaces
SoftwareOS Description Installed Applications and versions with process ID information Logical Disks Filesystems HTTP get on port 80
Inventory via SSHSoftwareOperating System OS Version OS Distribution OS Distribution Version CPU Architecture
Performance vis SNMP and SSHStatisticalCPU Performance Memory Performance (bytes used / % used) Physical Disk I/O Running Processes Socket Connectivity Information (uses TCP-MIB via SNMP / prefers RFC 4022 version) Network Interface Utilization

VMware

For VMware Servers, the following information is collected:

TypeCategoryInformation Collected
InventoryHardwareServer Model Network Connectivity Physical Memory CPU Disk Information (size and configuration)
SoftwareGuest Inventory OS Version ESX Location Host Inventory OS Version DataStore mapping to hosts and guests
OperationalVirtual Switch configuration
PerformanceStatisticalCPU Utilization (wait time, ready time, etc) Memory Utilization (usage MB, etc) Disk Utilization (I/O / sec, bytes/sec, etc) Network Utilization (bytes in/out)

Databases

For databases, the following information is collected.

TypeCategoryInformation Collected
InventoryDatabaseHostname Version Schemas Names (sometimes referred to as database names) Connectivity Table Metadata Table Names
PerformanceStatisticalConnectivity Table Names