The Timeline displays an interactive listing of all traffic that occurred within the given file set or originated from the selected host(s). Each block within the timeline represents a point in time where data was transferred over the network. Hovering over a protocol block will display the amount of data transferred within the given time period. Clicking on a block will populate the Inspector panel with detailed information about the connection(s) that took place during the given time period.
When the Smart Filter is activated (by default), selecting a host within the topology will update the timeline to display only the protocols created by the selected host(s).
NOTE: Timeline blocks are NOT generated for bro/zeek logs.
Protocol Listing
The protocol listing on the left side of the timeline is composed of all identified protocols existing within the given file set or host selection. Clicking on a protocol header will expand the protocol tree to display all protocol blocks of the given type.
Clicking on the protocol header will select all blocks for the selected protocol.
Timeline
The interactive timeline can be shortened, expanded, marked, and clicked on to allow users to fine-grain their analysis.
Timeline Searching
The timeline search text field allows users to find a specific protocol within the current data set. Simply enter the desired protocol and the timeline will update to display all matching protocols.
Timeline Zooming
Users can zoom in and out of the timeline by clicking and dragging the timeline handles or by holding down CTRL + mouse scroll wheel.
Upon zooming into the timeline, individual protocol blocks will appear at specific points in time.
Timeline Events
Timeline events are used to inform the user of login activity or potential malicious activity including network scanning and injection attacks.
Clicking on an Authentication Event will display plain text login credentials within the Inspector panel > Selected Events section.
To select multiple events or blocks, hold down the SHIFT key and drag the mouse over the desired data.
Timeline Export (Teleflow)
The Timeline can now be exported to a CSV file. Users can export the full timeline, the current view, or the currently selected traffic.