Monitor Enterprise
VeloCloud SD-WAN allows an Enterprise user to monitor the events and services using a redesigned portal.

You can explore each monitoring option and select the graphs to view more detailed drill-down reports.
- Search – Enter a term to search for specific details. Select the Filter icon to filter the view by a specific criterion.
- Column – Select the columns to show or hide in the view.
- Refresh – Select to refresh the details displayed with the most current data.
Monitor Network Overview
The Network Overview page displays the overall summary of the network, including activated Edges, links, top applications, and other configured data.
To view the Network Overview summary:
In the SD-WAN service of the Enterprise portal, select .
The Network Overview page displays the summary of the network in a graphical representation. On this page, you can find details about Activated Edges, Links, Top performing Applications and Edges by data volume, Profiles used by the Edges, Activated Segments, Software version of the Edges, and more.
Also, the Network Overview page displays additional information about the Edges connected, degraded, and down in a table format. For a provisioned and activated Edge, you can find additional details such as name and status of Edge, number of links and hub links that are stable, name of Cluster to which the Edge is assigned, High Availability (HA) mode if the Edge is running 5.2.0.0 and above versions, Bastion state if configured, secrets encryption, and date/time when the Edge activated.

The following details are displayed:
| Option | Description |
|---|---|
| Activated Edges | Displays the number of Edges and Hubs that are connected, degraded, and down, along with a graphical representation. Select the link to a number and details of the corresponding Edges or Hubs are displayed in the bottom panel.
In the following table, select the link to the Edge or the cluster name to navigate to the corresponding tabs. |
| Links | Displays the number of links and hub links that are stable, degraded, and down, along with a graphical representation. Select the link to a number and details of the corresponding links or Hub links are displayed in the bottom panel.
In the following table, select the link to the Hub name to navigate to the corresponding tab. |
| Top Apps by Data Volume | Displays the top 10 applications sorted by volume of data. |
| Top Edges by Data Volume | Displays the top 10 Edges sorted by volume of data. |
| Profiles Used | Displays the details of used and unused profiles. |
| Segments Activated | Displays the details of activated and other segments. |
| Software Version | Displays the details of software versions of the Edges, that are up to date and outdated. |
| Edges with Enabled VNF | Displays the number of Edges activated with VNF, that are with status Error, Off, and On. |
| Edges with Enabled A-S Pair | Displays the number of Edges activated as Active-Standby pair, that are with status Failed, Pending, and Ready. |
| Non SD-WAN Destinations via Gateway | Displays the number of non SD-WAN destinations that are connected and offline. |
Hover the mouse on the graphs to view additional details.
Monitor Security Overview
The Security Overview page displays the overall impact summary of configured Security services, like Intrusion Detection System (IDS)/Intrusion Prevention System (IPS), URL Categories, URL Reputations, and Malicious IP for all Edges within an Enterprise, based on the metrics collected using the various Enhanced Firewall Services (EFS) engines (IDS/IPS/URL Filtering/Malicious IP).
Monitor Security Overview - Enterprise View

| Option | Description |
|---|---|
| Overall Impact Summary | Displays the total count of Edges within the Enterprise and total count of Reporting Edges whose traffic was subjected to at least one of the Enhanced Firewall Engines.
Under Reporting Edges, selecting the link to the number displays a tabular view of all Edges whose traffic hit at least one EFS engine along with the Action count details. Hover the mouse over the Action count to view the split count by supported Action types. ![]() To view the EFS Threats details for a specific Edge, select the link to the Edge name. You will be navigated to the Edge-specific Security Overview page. See Monitor Security Overview. |
| IDS/IPS Summary | Displays the total count of IDS/IPS Threats Detected and Prevented for all Edges within the Enterprise, along with the Threat Severity and Action details in a graphical representation. Hover the mouse on the graphs to view specific threat details.
For detailed information about the IDS/IPS Threat distribution, see the section Monitor Security Overview. |
| URL Category Summary | Displays the total count of URL Categories and Action count details for all Edges within the Enterprise, along with the Top 5 URL Categories details in a graphical representation.
For detailed information about the URL Category Threats distribution, see the section Monitor Security Overview. |
| URL Reputation Summary | Displays the total count of URL Reputation risks and Action count details for all Edges within the Enterprise in a graphical representation.
For detailed information about the URL Reputation Threats distribution, see the section Monitor Security Overview. |
| Malicious IP Summary | Displays the total count of Malicious IP Blocked and Monitored.
For detailed information about the Malicious IP Threats distribution, see the section Monitor Security Overview. |
Monitor IDS/IPS
To view the IDS/IPS specific threats details for an Enterprise, select .
- Impacted Edge Distribution – Represents a map view of all the IDS/IPS Impacted Edges (by severity) and Protected Edges. The page graphically displays the following IDS/IPS Threat details for an Enterprise:
- Total count of Edges Impacted
- Total count of Edges Protected
- Top Threats Detected filtered "By Count" (Default) or "By Impact"
- Top Threat Origins filtered "By Country" (Default) or "By IP Address"
- Top Impacted Edges filtered "By Edge Name"
- Top Impacted Clients filtered "By IP Address"
Figure 5. Security Overview- Edge Distribution 
- Impacted Edge List – Represents a tabular view of all the IDS/IPS impacted Edges along with Threat details. The page displays the following details: Name and Description of the impacted Edge, Threat Impact on Edge, and Status of impacted Edge.
Figure 6. Security Overview- IDS/IPS 
Monitor URL Filtering

- Total count of URL Categories
- Total count of URL Category Actions
- Top URL Categories
- Top URL categories filtered by "Action" (Blocked, Allowed, and Monitored) or "Total Count" (Default)
- Top Edges filtered by "Category Actions" (Blocked, Allowed, and Monitored) or "Total Count" (Default)
- Total count of URL Reputations
- Total count of URL Reputation Actions
- Top Websites filtered by "URL Reputation" (High Risk, Suspicious, Medium Risk, Low Risk, and Trustworthy) or "Total Count" (Default)
- Top Edges filtered by "Reputation Actions" (Blocked, Allowed, and Monitored) or "Total Count" (Default)
Monitor Malicious IP

- Total count of Blocked Malicious IP
- Total count of Monitored Malicious IP
- Top Malicious Destination IPs filtered by "Action" (Blocked and Monitored) or "Total Count" (Default)
- Top Malicious Categories filtered by "Action" (Blocked and Monitored) or "Total Count" (Default)
- Top Edges filtered by "Action" (Blocked and Monitored)) or "Total Count" (Default)
- Top Malicious Destination Countries filtered by "Action" (Blocked and Monitored) or "Total Count" (Default)
Monitor Security Overview - Edge View
- In the SD-WAN service of the Enterprise portal, select . The list of Edges associated with the Enterprise appears.
- Select an Edge by selecting the link to an Edge. The Network Overview page (default page view) appears.
- From the Network Overview drop-down menu, select Security Overview.
The Security Overview page displays the overall impact summary of configured Security services, like IDS/IPS, URL Categories, URL Reputations, and Malicious IP for the selected Edge.
Figure 9. Monitor Security - Edge 
Monitor Edges
You can monitor the status of Edges and view the details of each Edge, like the WAN links, top applications used by the Edges, usage data through the network sources and traffic destinations, business priority of network traffic, system information, details of Gateways connected to the Edge, and so on.
To monitor the Edge details:

Select CSV to download a report of the Edges in CSV format.
Select View in the Gateways column to view the details of the Gateways connected to the corresponding Edge.
Select an Edge name in the Name column to view the details of the selected Edge. Select the relevant tabs to view the corresponding information. Each tab displays a drop-down list at the top which allows you to select a specific time period. The tab displays the details for the selected duration.
Some of the tabs provide drop-down menu of metrics parameters. You can choose the metrics from the list to view the corresponding data. The following table lists the available metrics:
The following table describes each drop-down menu that are available in the Links, Applications, Sources, Destinations, and Business Priority tabs.
| Metrics Option | Description |
|---|---|
| Average Throughput | Total bytes in a given direction divided by the total time. The total time is the periodicity of statistics uploaded from the Edge. By default, the periodicity in Orchestrator is 5 minutes. |
| Total Bytes | Total number of bytes sent and received during a network session. |
| Bytes Received/Sent | Split up details of number of bytes sent and received during a network session. |
| Total Packets | Total number of packets sent and received during a network session. |
| Packets Received/Sent | Split up details of number of packets sent and received during a network session. |
| Bandwidth | The maximum rate of data transfer across a given path. Displays both the upstream and downstream bandwidth details. |
| Latency | Time taken for a packet to get across the network, from source to destination. Displays both the upstream and downstream Latency details. |
| Jitter | Variation in the delay of received packets caused by network congestion or route changes. Displays both the upstream and downstream Jitter details. |
| Packet loss | Packet loss happens when one or more packets fail to reach the intended destination. A lost packet is calculated when a path sequence number is missed and does not arrive within the re-sequencing window. A “very late” packet is counted as a lost packet. |
| Auto Dual-Mode SIM | Status of the Edge with respect to the Automatic Switchover feature configured on that Edge, and is applicable only for a 610-LTE. For additional information on the Automatic Switchover feature, see Configure Automatic SIM Switchover. |
| Signal | Signal strength of the Edge indicated by the number of bars. |
The following table describes the filter options that are available in the Applications, Sources, and Destinations tabs.
| Filter Option | Description |
|---|---|
| Application | The application used by the Edge. |
| Category | The category of the application used by the Edge. |
| Operating System | The operating system used by the Edge. |
| Hostname | The hostname associated with the flow. |
| IP Address | The IP address associated with the flow. |
| Client Device | The Client device associated with the flow. |
| Destination | The destination domain of the flow. |
| Destination IP | The destination IP address of the flow. |
| FQDN | The Fully Qualified Domain Name (FQDN) of the flow. |
| Next Hop | The Next hop SD-WAN destination for the flow based on indicated Route. |
| Route | The WAN route taken by the flow. Refer to table Route to Next Hop Mapping for description of each route and its relation to Next hop. |
| Route Name | Nexthop |
|---|---|
| cloudViaGateway | The name of the Gateway that routes traffic to the cloud. |
| internetViaDirectBreakout | Nexthop has no name. The traffic is coming from the Internet directly. |
| branchToBranch (Gateway) | The name of the Gateway responsible for routing traffic to the other branch. |
| branchToBranch (Edge) | The name of the Edge that was used to route traffic to the other branch. |
| branchToNVSDirect | The name of the HUB device serving as the nexthop Edge. |
| branchToNVSViaGateway | The name of the Gateway that routes traffic to NVS. |
| branchToBackhaul | The name of the Edge or enterprise object that is used to route traffic to a non-velocloud site. |
| cloudViaGateway (Edge – to Partner Gateway) | The nexthop is the name of the Partner Gateway that will route the traffic. |
| branchRouted | Nexthop has no name. For basic routed traffic, there is no destination object, specifically, via an Edge router. |
| internetViaBranchCSS | Name of enterprise object used to route traffic to a non-VeloCloud branch. |
- Overview
- QoE
- Links
- Paths
- Flows
- Applications
- Sources
- Destinations
- Business Priority
- System
- High Availability
- Configure – Navigates to the Configuration tab of the selected Edge. See Configure Edges with New Orchestrator UI.
- View Events – Displays the Events related to the selected Edge.
- Remote Diagnostics – Allows to run the Remote Diagnostics tests for the selected Edge. See Run Remote Diagnostics.
- Generate Diagnostic Bundle – Allows to generate Diagnostic Bundle for the selected Edge. See Diagnostic Bundles for Edges with New Orchestrator UI.
- Remote Actions – Allows to perform the Remote actions for the selected Edge. See Perform Remote Actions with new Orchestrator UI.
- View Profile – Navigates to the Profile page, that is associated with the selected Edge.
- View Gateways – Displays the Gateways connected to the selected Edge.
| Option | Description |
|---|---|
| Search | Enter a search term to search for the matching text across the page. Use the advanced search option to narrow down the search results. |
| Columns | Select and select the columns to be displayed or hidden on the page. |
| Refresh | Select to refresh the page to display the most current data. |
Monitor Edge Overview
The Overview tab of an Edge in the monitoring dashboard displays the details of WAN links along with bandwidth consumption and network usage.
- In the SD-WAN service of the Enterprise portal, select to view the Edges associated with the Enterprise.
- Select the link to an Edge and display the Overview tab.
The Overview tab displays the details of links with status and the bandwidth consumption.

You can choose whether to view the Edge information live using the Live Mode option. When this mode is ON, live monitoring of the Edge happens and the data in the page is updated whenever there is a change. The live mode is automatically moved to offline mode after a period of time to reduce the network load.
The Links Status section displays the details of Links, Link Status, Auto Dual-Mode SIM, WAN Interface, Throughput, Bandwidth, Signal, Latency, Jitter, and Packet Loss. For additional information on these parameters, see Monitor Edges.
The Top Consumers section displays graphical representation of bandwidth and network usage of the following: Applications, Categories, Operating Systems, Sources, and Destinations of the Edges. Select View Details in each panel to navigate to the corresponding tab and view additional details.
Hover the mouse on the graphs to view additional details.
Monitor QoE
The VeloCloud Quality of Experience (QoE) tab displays the Quality Score for different applications. The Quality score rates an application's quality of experience that a network can deliver for a period of time. The QoE is calculated based on the best score comparing all the Static tunnels (Edge to Gateways and Edge to Hubs) and then displays the best performing tunnel.
- In the SD-WAN service of the Enterprise portal, select to view the Edges associated with the Enterprise.
- Select the link to an Edge, and then select the QoE tab.
The QoE tab displays the quality score of applications for different traffic types.

- Voice
- Video
- Transactional
| color | Rating Color | Rating Option |
|---|---|---|
| Green | Good | All metrics are better than the objective thresholds. Application SLA is met/exceeded. |
| Yellow | Fair | Some or all metrics are between the objective and maximum values. Application SLA is partially met. |
| Red | Poor | Some or all metrics have reached or exceeded the maximum value. Application SLA is not met. |
To modify the threshold values, select the View/Modify Thresholds link located at the bottom of the screen, which takes you to the page.
Monitor Links of an Edge
You can monitor the WAN links connected to a specific Edge along with the status, interface details, and other metrics.
To view the details of Links and Transport groups used by the traffic:
- In the SD-WAN service of the Enterprise portal, select to view the Edges associated with the Enterprise.
- Select the link to an Edge, and then select the Links tab.
The Links tab displays the details of WAN links connected to the selected Edge.

At the top of the page, you can choose a specific time period to view the details of the priorities for the selected duration.
By default, the Scale Y-axis evenly check box is selected. This option synchronizes the Y-axis between the charts. If required, you can turn off this option.
Hover the mouse on the graphs to view additional details.
Select Transport Groups to view the links grouped into one of the following categories: Public Wired, Public Wireless, or Private Wired.
You can choose whether to view the information live using the Live Mode option. When this mode is ON, you can view live monitoring of the links and the transport groups.
Choose the metrics from the drop-down to view the details related to the selected parameter.
The bottom panel displays the details of the selected metrics for the links or the transport groups. You can view the details of a maximum of 4 links at a time.
Select the arrow prior to the link name or the transport group to view the break-up details. To view drill-down reports with additional details, select the links displayed in the metrics column.

Select the arrow next to Top Applications to navigate to the Applications tab.
Monitor Path Visibility
Path is a tunnel between two endpoints. Path visibility is a report on utilization and quality of the paths between an Edge and its VeloCloud SD-WAN peers. Orchestrator allows an Enterprise user to monitor the Path visibility using the monitoring dashboard.
For a selected Edge, you can monitor the Path information for the VeloCloud SD-WAN peers with traffic flow observed for a specific period.
- In the SD-WAN service of the Enterprise portal, select to view the Edges associated with the Enterprise.
- Select the link to an Edge, and then select the Paths tab.

At the top of the page, you can choose a specific time period to view the details of the priorities for the selected duration.
To get a report of a VeloCloud SD-WAN peer in CSV format, select the peer and select Export Path Statistics.
- All the VeloCloud SD-WAN peers that have traffic observed during the selected time period.
- The status of the paths available for a selected peer.
- Overall quality score of the paths for a selected peer for voice, video, and transactional traffic.
- Time series data for each path by metrics like: Throughput, Latency, Packet loss, Jitter, and so on. For additional information on the parameters, see Monitor Edges.

The metrics time-series data is displayed in a graphical format. You can select and view the details of a maximum of four paths at a time.
By default, the Scale Y-axis evenly check box is selected. This option synchronizes the Y-axis between the charts. If required, you can turn off this option.
Hover the mouse on the graphs to view additional details.
Expand the Quality Score pane at the top, to view the Path score by the traffic types.

You can select a VeloCloud SD-WAN peer displayed in the left pane, to view the corresponding Path details.
A black vertical dotted line indicating an anchor, appears on the graph, whenever there is a threshold value change in a Profile or an Edge. You can hover the mouse on the anchor to see the modified latency threshold values for Voice, Video, and Transactional. To modify the threshold values, select the View/Modify Thresholds link located at the bottom of the screen, which directly takes you to the page.
Monitor Flow Visibility
The Flow Visibility feature introduces a new Flows tab under , which provides detailed flow data on each traffic flow for each Edge. The comprehensive end-to-end flow (non-live flow) is built based on certain flow parameters, such as Source IP, Destination IP, Destination Port, Protocol, and Link ID. These parameters are displayed in a single-view table format, which can assist with monitoring and troubleshooting non-live flows. Starting with the 6.1 release, the Live Mode monitoring feature is supported. The Live Mode monitoring gives visibility into Source Port on top of non-live flows. It allows you to select individual or multiple live flows (up to four flows) to monitor and compare their metrics as live time series graphs.
Monitoring Non-Live Flows
To view detailed non-live flow data for a selected Edge, perform the following steps:
The Search field provides search capabilities to find a specific flow. Enter a search string to find text that matches the Source IP, Destination IP, Destination FQDN, and Destination Domain fields. Use the Advanced Search feature for more advanced filtering criteria.
Select the Filter icon to define a filter criterion. You can filter the flow details by the specified criteria: Source IP, Destination IP, Destination Port, Segment, Host Name, Application, Category, Destination FQDN, Destination Domain, and Next Hop.
Monitor Live Flows
"edge.liveData.enterFlowLiveMode.delay.seconds" and "edge.liveData.enterFlowLiveMode.flow.count" System Properties. See section "List of System Properties" in the Operator Guide for a description of these properties and information on how to configure them.
To activate Live Mode flow monitoring, perform the following steps:
By default, the Scale Y-axis evenly check box is selected. This option synchronizes the Y-axis scale between the two charts. If required, you can turn off this option.
Monitor Edge Applications
You can monitor the network usage of applications or application categories used by a specific Edge.
To view the details of applications or application categories:
At the top of the page, you can choose a specific time period to view the details of the priorities for the selected duration.
Monitor Edge Sources
You can monitor the network usage of devices and operating systems for a specific Edge.
To view the details of devices and operating systems:
The Sources tab displays the details of the client devices used by the selected Edge.

At the top of the page, you can choose a specific time period to view the details of the priorities for the selected duration.
By default, the Scale Y-axis evenly check box is selected. This option synchronizes the Y-axis between the charts. If required, you can turn off this option.
Hover the mouse on the graphs to view additional details.
Monitor Edge Destinations
You can monitor the network usage data of the destinations of the network traffic.
To view the details of destinations, use the following steps:
Monitor Business Priorities of an Edge
You can monitor the Business policy characteristics according to the priority and the associated network usage data for a specific Edge.
To view the details of business priorities of the network traffic:
The Business Priority tab displays the details of the priorities of the network traffic for the selected Edge.

At the top of the page, you can choose a specific time period to view the details of the priorities for the selected duration.
Monitor System Information of an Edge
Starting from the 6.1.0 release, the System tab displays not only the detailed network usage by the system for a specific Edge, but also the system health statistics for an HA Standby Edge.
To access the System tab, use the following steps:
Monitor Network Services
You can view the details of configured network services for an enterprise.
To view the details of network services, log in to the SD-WAN service of the Enterprise portal, and then click .
Monitor Non SD-WAN Destinations through Gateway
You can view the configured Non SD-WAN Destinations along with the VPN Gateways, Site Subnets, and other configuration details.
To view the configured Non SD-WAN Destinations:
In the SD-WAN service of the Enterprise portal, select . The Non SD-WAN Destinations via Gateway tab is displayed.
The Non SD-WAN Destinations via Gateway tab displays the details of already configured Non SD-WAN Destinations. To configure the Non SD-WAN Destinations via Gateway, see Configure Non SD-WAN Destinations via Gateway.





| Options |
|---|
| Total Bytes |
| Bytes Received/Sent |
| Total Packets |
| Packets Received/Sent |
- Non SD-WAN Destination Name
- Public IP Address
- Non SD-WAN Destination Status
- Tunnel Status
- Number of profiles and Edges using the Non SD-WAN Destination
- Last Contacted date and time
You can also sort the report by selecting the header of each column. You can use the Filter icon displayed next to the header to filter the details by specific Name, IP address, or Status.
Select a Non SD-WAN Destination to view the following details in the bottom panel:
| Options | Description |
|---|---|
| General | Displays the Name, Type, IP address and tunnel settings of Primary and Secondary VPN Gateways, location details, and Site subnet details. |
| IKE/IPSec Configuration | Select the tab to view sample configuration template for Primary and Secondary VPN Gateways. You can copy the template and customize the settings as per your requirements. |
| Events | Select the tab to view the events related to the selected Non SD-WAN Destination. Selectthe arrow displayed in the first column to view additional details of an event. |
| Monitoring | Select the tab to view the NSD tunnels display statistics in both table and chart format of the Bytes, Packets sent and received. |
Monitor Non SD-WAN Destinations through Edge
You can view the configured Non SD-WAN Destinations along with the VPN Gateways, Site Subnets, and other configuration details.
To view the configured Non SD-WAN Destinations through Edge:
In the SD-WAN service of the Enterprise portal, select . The Non SD-WAN Destinations via Edge tab appears.
The Non SD-WAN Destinations via Edge tab displays the details of already configured Non SD-WAN Destinations. To configure the Non SD-WAN Destinations via Edge, see the topic Configure Non SD-WAN Destinations via Edge.

- Name of the Non SD-WAN Destination
- Public IP Address
- Status of the tunnel
- Number of Profiles
- Edges that use the Non SD-WAN Destination, last contacted date and time, and deployment status of Edge
You can also sort the report by selecting the header of each column. You can use Filter displayed next to the header to filter the details by specific Name, IP address, or Status.
Selecting a Non SD-WAN Destination displays Name, Type, IP address and tunnel settings of Primary and Secondary VPN Gateways, location details, and Site subnet details under the General tab.
Monitor Cloud Security Service Sites
You can view the details of Cloud Security Services (CSS) configured for the Enterprise.
To monitor the Cloud Security Services:
In the SD-WAN service of the Enterprise portal, select .
The Cloud Security Service Sites tab displays the already configured Cloud Security Services. To configure a new Cloud Security Service, see Cloud Security Services.

| Column Name | Description |
|---|---|
| Name | Name of the CSS service provider. |
| Type | Type of the CSS service provider. |
| Public IP | IP address of the CSS service provider. |
| Status | Overall status of the CSS service provider. |
| Tunnel Status | Status of tunnels created from the CSS provider from different Edges. Also, status of the external service as recorded by each Edge |
| Deployment Status | Deployment status of the CSS provider. |
You can also sort the report by selecting the header of each column. You can use the Filter icon displayed next to the header to filter the details by specific Name, Type, IP address, or Status.
Select the View link in the Deployment Status column to view the deployment status of the CSS provider.
- L7 health check status data is available through API only.
- To view related tunnel state change events, navigate to , and filter by CSS tunnel events.
Monitor Zscaler laasSubscription
You can view the configured Zscaler laasSubscription from the Monitor > Network Services page.
To view the Zscaler laasSubscription:
In the SD-WAN service of the Enterprise portal, click .
The Zscaler laasSubscription tab displays the details of already configured Zscaler laas subscriptions. To configure a new Iaas subscription, see Configure API Credentials.

The page displays the name of the service along with the deployment status.
Monitor Edge Clusters
You can view the details of the configured Edge clusters and the usage data.
You can view the details of Edge clusters from the SD-WAN service of the Enterprise portal. Select .
The Edge Clusters tab displays the details of already configured Edge clusters. To configure the clusters, see Configure Edge Clustering.

| Option | Description |
|---|---|
| Cluster Name | Name of the Cluster as configured under . |
| Edges | Name of the Hub Edges that are a part of this Cluster. |
| CPU Utilization | Percentage value of CPU utilization of the corresponding Edge. |
| Memory Utilization | Percentage value of memory utilization of the corresponding Edge. |
| # Tunnels | Number of tunnels associated with the Hub Edge that is a part of the Cluster. |
| Flow Count | Number of flows associated with the Hub Edge that is a part of the Cluster. |
| # Handoff Queue Drops | Number of packets that are dropped when they exceed over capacity of Hub Edge in the Cluster. |
Monitor Edge VNFs
You can view the details of the configured Edge VNFs and the VM status.
To view the Edge VNFs:
In the SD-WAN service of the Enterprise portal, select .
The Edge VNFs tab displays the details of already configured VNFs. To configure VNF on an Edge, see Configure Edge Services.

The page displays the following details: Name of the VNF Service, Number of Edges that use the VNF, and VM status.
Select on a VNF to view the corresponding VNF Edge deployment details.
Monitor Routing Details
You can view the routing services configured in the Enterprise.
Monitor Multicast Groups
You can view the multicast groups configured for the Enterprise.
To view the multicast groups:
In the SD-WAN service of the Enterprise portal, select . The Multicast Groups tab is displayed.
The Multicast Groups displays the details of already configured multicast group settings. To configure multicast groups, see Configure Multicast Settings for Profiles.

The page displays the following details: multicast group address, segment that consist of the multicast group, Source IP address, RP address, number of Edges in the multicast group, created time period, and the last updated time period.
Select a multicast group to view the details of the Edges in the group, along with the upstream and downstream information. Select View PIM Neighbors to view the detail of the PIM neighbors connected to a specific Edge.
Monitor PIM Neighbors
You can view the details of Edges and the PIM neighbors available in the multicast groups.
To view the PIM neighbors:
In the SD-WAN service of the Enterprise portal, select .
The PIM Neighbors tab displays the Edges available in the multicast groups.

Select an Edge to view the PIM neighbors connected to the Edge. The PIM Neighbors section displays the following details: Segment of the multicast group, Edge name, Interface details, IP address of the neighbor, created and last updated date with time.
Monitor BGP Edge Neighbor State
You can view the details BGP neighbors connected to Edges.
To view the BGP neighbors connected to Edges:
In the SD-WAN service of the Enterprise portal, select .
The BGP Edge Neighbor State tab displays the Edges connected as BGP neighbors, when you have configured BGP settings on the Edges.

The page displays the following details: Edge name, IPv4 and IPv6 address of the neighbor, State of the neighbor, Date and time of the state change, number of messages received and sent, number of Events, duration for which the BGP neighbor is Up/Down, and number of prefixes received.
Select an Edge name to view the corresponding event details. The Related State Change Events section displays the change in the state and other details for the selected Edge.
- You can select the Filter Icon next to the Search option to filter the details by Edge Name, Neighbor IP, Neighbor IP Type, and Status.
- BGP Edge Neighbor State (API:
monitoring/getEnterpriseEdgeBgpPeerStatus): At the time of calling the API, if the Edge state is "OFFLINE", then the user interface displays the neighbor state as "Unavailable" with appropriate tooltip showing the current Edge state to the user.
Monitor BFD
You can view the BFD sessions on Edges and Gateways.
To view the BFD sessions:
In the SD-WAN service of the Enterprise portal, select .

The page displays the following details for the Edges and Gateways: Name of the Edge or Gateway, Segment name, Peer IP address, Local IP address, State of the BFD session, Remote and Local timers, number of Events, and duration of the BFD session.
Select the link to an event number to view the break-up details of the events.
Monitor BGP Gateway Neighbor State
You can view the details of the BGP neighbors connected to Gateways.
To view the BGP neighbors connected to Gateways, follow the steps below.
Gateway Route Table
The Gateway Route Table provides a comprehensive view of the routing information on an SD-WAN Gateway, displaying the routes (up to 16k) that are known to a Gateway, including both learned routes and statically configured routes.
The Gateway Route Table displays important information about each route, such as the Network Prefix and Mask Preference, Flags, and Metric, to name a few. The Gateway Route Table updates in real-time, providing an up-to-date view of the routing information on a Gateway. It can be used to diagnose routing issues and to optimize routing policies.
To access the Gateway Route Table:
In the SD-WAN service of the Enterprise portal, select , as shown in the image below.

| Field | Description |
|---|---|
| Network Prefix | The destination address of the route. It specifies the network to which the route applies. |
| Network Mask | Displays the prefix carried by the BGP route. |
| Type | Indicates the type of routes:
|
| Peer Name | Indicates the name of the BGP peer that learned the route. |
| Reachable | Indicates whether the route is reachable or not. If the route is reachable, it can be used for forwarding packets. |
| Metric | A value that represents the cost of using a particular route. Lower values indicate a lower cost. |
| Preference | A value that is used to influence the preferred path for outbound traffic. A lower value indicates a more preferred route. |
| Flags | Flags are listed below:
|
| Age | Indicates the amount of time that has elapsed since the route was last updated. |
| C Tag | Used to identify the customer that the route belongs to in a multi-tenant environment. |
| CSV | Select the CSV button to export the data to an Excel sheet. |
Monitor Alerts
Orchestrator allows to configure alerts that notify the Enterprise Administrators or other support users, whenever an event occurs.
Ensure that you have configured the relevant alerts, along with the notification delay, in . See Configure Alerts and Notifications.
In the SD-WAN service of the Enterprise portal, select .

You can choose a specific time period from the menu, to view the alerts for the selected duration.
To view details of specific alerts, you can use the filter option. Select the Filter icon in the Search option to define the criteria.
Select the CSV option to download a report of the Alerts in CSV format. You can also choose to include the Operator alerts.
The Alerts window displays the following details:
| Option | Description |
|---|---|
| Incident | The name of the event that triggered the alert. |
| Incident Category | The category of the incident. |
| Affected Entity | The entities (Edge/Link) affected by the incident. |
| Trigger Time | Time at which the alert got triggered. |
| Delivery Attempted Time | Time at which the operator or customer received the alert notification. The notification time depends on the delay time configured in the Alerts & Notifications page. |
| Status | Status of the alert as Success, Failed, or No Recipients. |
| Alert Level | Indicates if the alert received by the Operator or the Customer. |
Monitor Events
The Events page displays the events generated by the Orchestrator. These events help to determine the operational status of the system.
In the SD-WAN service of the Enterprise portal, select .

You can choose a specific time period from the list, to view the events for the selected duration. Select on an event name to view additional details.
To view details related to specific events, you can use the filter option. Select Filter in the Search option to define the criteria.
Select the CSV option to download a report of the events in CSV format.
The Events window displays the following details:
| Option | Description |
|---|---|
| Event | Name of the event |
| User | Name of the user for events that involve the user. |
| Segment | Name of the segment for segment related events. |
| Edge | Name of the Edge for Edge related events. |
| Severity | Severity of the event. The available options are: Alert, Critical, Debug, Emergency, Error, Info, Notice, and Warning. |
| Time | Date and time of the event. |
| Message | A brief description of the event. |
Auto Rollback to the Last Known Good Configuration
If an Administrator changes a device configuration that causes the Edge to disconnect from the Orchestrator, the Administrator receives an Edge Down alert. Once the Edge detects that it cannot reach the Orchestrator, it rollbacks to the last known configuration and generates an event, Bad Configuration, on the Orchestrator.
The rollback time, which is the time necessary to detect a bad configuration and apply the previous known good configuration for a standalone Edge, is between 5-6 minutes. For HA Edges, the rollback time is between 10-12 minutes.
Platform Firmware Upgrade Progress
You can view the progress of the Platform Firmware upgrade on the Orchestrator UI, as described in the sections below.
To view the progress for the Platform Firmware upgrade on the Orchestrator UI, go to . The Events page displays a list of events and shows the status of the Platform Firmware upgrade (In Progress or Installed).

Monitor Firewall Logs
The Firewall Logs page displays the details of the firewall log originating from VeloCloud Edges. Previously the only way a customer could store and view firewall logs was by forwarding them to a Syslog server. With Release 5.2.0 the customer has the option to store firewall logs on the Orchestrator where they can be viewed, sorted, and searched on the Orchestrator UI. By default, Edges cannot send Firewalls logs to Orchestrator. For an Edge to send the Firewall logs to Orchestrator, ensure you Enable Firewall Logging to Orchestrator activate the capability the Customer level under Global Settings. By default, Orchestrator retains the Firewall logs until it reaches the maximum retention time of seven days or a maximum log size of 15 GB per customer tenant on a rotation basis.
- Creation of a flow after accepting the flow.
- Closing a flow.
- Denying a new flow.
- Updating an existing flow due to a firewall configuration change.
- If a firewall rule has URL Categories filtering service activated, the URL Category engine looks up the categories of destination URLs and detects if that matches the Blocked or Monitor categories configured. If the URL matches the Blocked categories, the URL Categories engine generates an alert and blocks the Edge traffic. If the URL matches the Monitor categories, the engine allows the Edge traffic and captures the firewall logs.
- If a firewall rule has URL Reputation filtering service activated, the URL Reputation engine looks up the reputation score of the URL and takes action (Allow/Block) based on the minimum reputation configured. If the reputation score of the URL is less than the minimum reputation configured, the Edge blocks the traffic and generates EFS alerts and logs, otherwise allows the traffic. The URL Reputation engine generates EFS logs for the allowed traffic based on the Capture Logs configuration.
- If a firewall rule has Malicious IP filtering service activated, the Malicious IP engine checks if the destination IP is present in the Malicious IP Database (Network Query DB and Local DB). If the engine detects the destination IP in the Malicious IP database, then the engine generates EFS alerts and logs and takes Edge traffic decisions based on the configured action (Block/Monitor).
- If a firewall rule has only the Intrusion Detection System (IDS) activated, the Edges detect if the traffic flow is malicious or not based on certain signatures configured in the engine. If an attack is detected, the EFS engine generates an alert and sends the alert message to Orchestrator/Syslog Server if Firewall logging is activated in Orchestrator and will not drop any packets.
- If a firewall rule has Intrusion Prevention System (IPS) activated, the Edges detect if the traffic flow is malicious or not based on certain signatures configured in the engine. If an attack is detected, the EFS engine generates an alert and blocks the traffic flow to the client only if the signature rule has action as Reject, matched by the malicious traffic. If the action in the signature rule is Alert, the engine allows the traffic without dropping any packets even if you configure IPS.
To view the Edge Firewall logs in Orchestrator, use the following steps:
Enterprise Reports
VeloCloud SD-WAN allows you to generate exportable secure SD-WAN Enterprise reports based on historical data for selected or all Edges across the Enterprise. The Enterprise reports include Network and Security data that are useful for the analysis of network.
- Quick Report is a consolidated report generated with default values, including all the data for the past one month starting from the time of request, and for all the Edges currently present in the Enterprise network.
- Custom Report is a report generated with customized settings by specifying the time range, required data, and Edges to be included.
- Gen AI Traffic Report is a report on Generative AI (Gen AI) applications traffic within the network of an Enterprise.
vco.reporting.maxReportsPerEnterprise.
A report has 60 days of age-out period after which it will be deleted automatically. When a customer exceeds the maximum report value (i.e., the default is 50), the oldest report will be deleted first.
To access Enterprise reports:
In the SD-WAN service of the Enterprise portal, select .
In the Reports page, you can create a new Enterprise report, customize the report, and schedule report generation for a recurring period.

Create a Quick Enterprise Report
VeloCloud SD-WAN allows you to generate a consolidated report generated with default values, including all the data for the past one month starting from the time of request, and for all the Edges currently present in the Enterprise network. Note that the Quick report does not include the Gen AI Application traffic related information.
To create a Quick Enterprise report, perform the following steps:
Create a Custom Enterprise Report
You can create an Enterprise report with customized settings by specifying the time range, required data, and Edges. Custom report generation allows you to select and include Gen AI Application traffic as well.
Select Time Range
You can customize a report for a selected time period. In addition, you can schedule a report to run on recurring basis.
Select Data
You can select the data to be included in a custom report.
Select Edges
You can select to generate an Enterprise report including all the Edges or choose to include specific Edges.
Submit Report
After configuring all the settings, you can generate the Enterprise report.
Create a Generative AI Traffic Report for Enterprise
VeloCloud SD-WAN allows you to create a Generative AI (Gen AI) specific report for all Gen AI applications contributing to network traffic within an Enterprise.
To create a Gen AI Traffic report, perform the following steps:
Monitor Enterprise Reports
Generate a secure SD-WAN Enterprise report with Network and Security data using the default values, or a custom report with specified values, or a Gen AI specific report for Gen AI applications traffic. You can also schedule a custom report to run on a recurring basis. All the reports are displayed in the Reports page, where you can download and view the report data. You can also view the scheduled reports in this page.
In the SD-WAN service of the Enterprise portal, select . The page displays all the generated reports.

- PDF
- Graphical representation of distribution of Enterprise Traffic, Transport, and top Applications.
- Top 10 Applications by Traffic and Transport types.
- Top 10 Edges by Applications.
- Top Backup links with top Applications.
- Top Talkers with top Applications.
- Gen AI Traffic Report including the following details:
- Top Ten Gen AI Applications within the network of an Enterprise
- Top Ten Edges by Gen AI Applications
- Top Talkers across an entire Enterprise
- Top Ten Gen AI Applications presence across Edges
- Gen AI Applications Growth across Edges over time
- Top Edges in top Non SD-WAN Destinations from Edge.
- Top Sites in top Non SD-WAN Destinations via Gateway.
- Overall Impact Summary of the following data collected from all Enhanced Firewall Service (EFS) engines (IDS/IPS, URL Filtering, Malicious IP):
- Total Edges
- Reporting Edges
- Top Ten Reporting Edges and its Actions
- IDS/IPS Summary
- URL Category Summary
- URL Reputation Summary
- Malicious IP Summary
- IDS/IPS
- Top Ten Impacted Edges by Total Count
- Top Ten Impacted Edges by Critical and High Count
- Top Threats Detected
- URL Filtering
- Top Ten Edges By Category Actions
- Top Ten Edges By Category Blocked Actions
- Top Ten URL Categories By Action
- Top Ten Edges By Reputation Actions
- Malicious IP
- Top Ten Malicious Edges By Actions
- Top Ten Malicious Destinations By IP
- Top Ten Malicious Destinations By Country
- Top Ten Malicious Categories
Note: The Enterprise report PDF includes Security Summary, IDS/IPS, URL Filtering, and Malicious IP related data only when EFS is activated at the customer level. For additional information about monitoring Security Services, see Monitor Security Overview.
The following image shows an example snippet of a PDF report:
Figure 72. Displaying Enterprise Traffic Distribution
The Enterprise Traffic distribution lists the following data:- Cloud Via Gateway- Internet bound traffic that goes through the Gateway.
- Internet Via Direct Breakout- Internet bound traffic that breaks out directly from branch and does not go through Arista VeloCloud Tunnels.
- Internet Via Branch CSS- Traffic bound to Cloud Security Services directly from Arista VeloCloud branch.
- Branch To Branch- Traffic going through Gateway / Hub / dynamic SD-WAN Tunnels, directly between two Arista VeloCloud branches.
- Branch Routed- Traffic bound to local connected / static / routed (underlay) destinations.
- Branch To NVS Via Gateway- Traffic bound from branch to Non SD-WAN Destination through Gateway.
- Branch To NVS Direct- Traffic bound from branch to Non SD-WAN Destination over direct IPsec tunnels.
- Branch To Backhaul- Internet bound traffic being backhauled from branch to VeloCloud Hubs.
- CSV- downloads the following CSV files:
- Top Sites by Applications- Lists all the applications, Edge name, Edge description, Bytes transmitted, and Bytes received.
- Traffic Type- Lists all the flow paths, applications, Edge name, Edge description, Bytes transmitted, and Bytes received.
- Transport Type- Lists all the Transport types, applications, Edge name, Edge description, Bytes transmitted, and Bytes received.
- Backup Link Usage- Lists the names of all the Backup links, total bytes and applications used by the links, Bytes transmitted, and Bytes received.
- Non SD-WAN Destinations from Edge- Lists all the Non SD-WAN Destinations connected directly from the Edges, name and description of the connected Edges, Bytes transmitted, and Bytes received.
- Non SD-WAN Destinations via Gateway- Lists all the Non SD-WAN Destinations connected through Gateways, name of the Gateway, Bytes transmitted, and Bytes received. This report also lists the name and description of the Edges connected to each destination along with the Bytes transmitted, and Bytes received.
- Top Talkers- Lists the names of clients, source IP address, source MAC address, name and description of the Edges connected to each client, total bytes used by the client, applications, Bytes transmitted, and Bytes received.
- Gen AI Traffic Report- A comprehensive summary of traffic usage based on Gen AI applications detected in the network. Details include Top 10 Applications, Top 10 Edges per top application, Top Talkers per top edge per top application, footprint of top application across all edges and growth of footprint of top application across all edges over the past year.
- Security Summary- Lists all the Reporting Edges and total action count by category (IDPS, URL Category, URL Reputation, and Malicious IP).
- IDPS Edge Stats- Lists all the impacted Edges and total count by severity (Critical, High, Medium, Low, and Suspicious).
- IDPS Signature Stats- Lists all the signature names along with the severity and total count.
- URL Categories- Lists all the impacted Edges and total count by Category Actions (Blocked, Allowed, and Monitored).
- URL Reputation Stats- Lists all the impacted Edges and total count by Reputation Actions (Blocked, Allowed, and Monitored).
- Malicious IP- Lists all the impacted Edges and total count by Malicious Actions (Blocked and Monitored).
Note: For additional information about monitoring Security Services, see Monitor Security Overview.
The following image shows an example snippet of a CSV report for Top Sites by Applications:
Figure 73. Displaying a CSV Report 
To delete a report, select the report and select DELETE.
To view the scheduled reports, select RECURRING REPORTS.

The Recurring Reports window displays the details of reports and the recurrence schedule.
To remove a report from the scheduled list, select the report and select DELETE.
Monitor Security Service Edge
This screen is available only for Symantec PoP-to-PoP connectivity.

- Number of connected Gateways
- WSS Endpoint details
- Number of Profiles using this integration
- Number of locations associated
- Last updated date



























