Network Topology
Network Topology
A visualization that lays out network zones and IPs on isometric 3D platforms and replays detection event flows in time order.
- Platforms (boxes) are zones, and the dots on them are IPs.
- Zone type determines color and row placement — internet (red, top) → dmz (orange) → office (blue) → server_farm (green) → unclassified (gray, bottom).
- IP node color darkens from yellow to red with the risk level (number of distinct rules) in the selected range.
- Drag to pan and scroll to zoom.
Building Zones
A zone is a zone-type node in the knowledge graph. IPs land on a zone platform by these
rules, in order:
- Explicit membership — a
belongs-toedge fromipv4-addrtozoneplaces the IP on that zone. - Automatic CIDR assignment — set the zone node's
cidrattribute (e.g.10.0.1.0/24; multiple ranges separated by commas) and IPs in that range are placed on the zone automatically, without belongs-to edges. When ranges of several zones overlap, the narrowest range (longest prefix) wins. - Automatic grouping — IPs that belong to no zone are grouped into ad-hoc platforms: private addresses by /24, public addresses by ASN (or /24).
Zone name, type, and CIDR can also be edited as zone node properties in the Knowledge
Graph screen.
Time Range
Select the event window at the top right — 10 minutes / 1 hour / 6 hours / 12 hours / 24 hours. The default is 1 hour, and the last selection is remembered in the browser. The timeline's aggregation interval adjusts with the range (10 seconds for the 10-minute range up to 10 minutes for the 24-hour range).
Event Replay and Timeline
Detection events are drawn as arcs flying from the source IP to the destination IP. Arc color is the event priority (HIGH red / MEDIUM orange / LOW yellow tones).
Arcs replay in their actual order of occurrence. The timeline at the bottom of the screen shows the replay state.
- A histogram of event counts per interval (colored by the highest priority in the bucket).
- A vertical playhead marking the moment currently being replayed, with the time shown next to it.
- Click or drag on the timeline to seek to a moment.
- The button on the left toggles play/pause.
Node Details
Click an IP node to open the detail panel on the right; the replay pauses and the events involving that IP are shown as static arrows.
- Assigned employees — connected via
assigned-toedges. - Logged-in users — connected via
logged-inedges. - Events — recent detection events for the IP. Hovering an item highlights its arc.
Click empty space to deselect and resume the replay.
detection events. To place IPs on zones, create belongs-to edges or set the zone's cidr
attribute.
See Query Commands for populating the skeleton from firewall or NAC logs.