Understanding Failed TCP Connection Tracking in Trigger-it

You are here:
Estimated reading time: 1 min

By default, Trigger-it agent tracks all outgoing TCP connections that are being generated from any process on the managed PC, one of the cool outcomes is the ability to detect failed TCP connections and their corresponding processes.

Trigger-it tracks each connection with the generating process, if the connection has failed to reach its destination the connection is marked as failed in the connection table and Trigger-it will initiate a traceroute lookup to the destination IP and sends the response the Trigger-it Management server.

If the process has failed continuously to reach its destination, Trigger-it will ignore subsequent connections for 5 minutes, then perform the traceroute lookup and sends a feedback message to the server. This means that the server will receive a failed TCP connection for each connection across all the processes every 5 minutes.

The message is sent to the server and processed in Feedback Queue using Trigger-it Feedback Processes.

Was this article helpful?
Views: 106
Have questions? Search our knowledgebase.