---
title: "Monitor SD-WAN"
canonical: "https://docs.aryaka.com/space/KNOW/1609298/Monitor%20SD-WAN"
format: markdown
---
The SD-WAN > Monitor page displays a series of graphs that show traffic details for the selected site, traffic direction, and time period.  The top-level SD-WAN > Monitor page—and each child page that can be displayed from it—contains a primary graph that plots the page's primary statistic. Typically, it is a time series line graph displayed as the first graph (top left) on the page. For example, when you are on the SD-WAN > Monitor page, the primary graph is WAN Traffic. All other graphs on the page show WAN traffic-related graphs for the selected site. These graphs include WAN Traffic by Provider, WAN Traffic by Network, WAN Traffic by Zone, and so on. If you click VPN Path Aryaka in WAN Traffic by Network, the Network: VPN Path Aryaka page appears. It—and all other linked pages—have a similar structure to the top-level SD-WAN page. The primary graph on this page is Network Traffic: VPN Path Aryaka. All other graphs on the page show network traffic-related graphs. These graphs include Network Traffic by Provider, Network Traffic by Zone, Network Traffic by Application, and so on.  To open the SD-WAN > Monitor page Log in to MyAryaka. The Home page appears. Click  SD-WAN  >  Monitor  in the left navigation pane. The SD-WAN > Monitor page appears and displays graphs for a default site. Click the Reference Site drop-down menu and select the site you want to monitor. The components of the SD-WAN > Monitor page are described in the following sections.     Apply filters The filter pane contains the following components that allow you to select the criteria that determines the graph details that appear on the page.  Component Description Traffic Direction field Select one of the following options to determine the direction of the traffic flow for the selected reference site: Inbound Only—Graphs traffic received at the site. Outbound Only—Graphs traffic leaving the site. Time field Determines the period for which to monitor and graph the traffic for the selected reference site. Each time period has an associated data interval defined for it. For example, if you select the Last 24 Hours time period, the associated data interval is 1 minute, which means a sample is taken and graphed every minute for a 24 hour period. Select one of the following time period/data interval pairs to graph the selected site's traffic: Last 1 Hour (1 minute) Last 4 Hours (1 minute) Last 8 Hours (1 minute) Last 24 Hours (1 minute) Last 7 Days (30 minutes) Last 30 days (30 minutes) Last Day (1 minute) Last Week (30 minutes) Last Month (30 minutes) Current Month (30 minutes) Custom (varies per custom time period defined) Note:  Last Day is different from Last 24 Hours. The Last 24 Hours plots graph with traffic collected in the last 24 hours. Last Day plots the traffic during the last calendar day. Similarly, Last Month plots the traffic during the last calendar month, and so on. Current Month plots the traffic during the current calendar month. You can select a custom time, date, and year going as far back as five years. Apply button Saves and applies your filter selections to the page's graphs. Common graph elements The graphs section displays a series of graphs based on the selections made in the filter fields. Each graph includes the following components: A title that indicates what data is being presented. This could be the network type or the traffic direction as determined by an applied filter. An Expand icon that displays the graph fitted in the full page width. When expanded, the icon toggles to display the Collapse icon that displays the graph in its original width. An Options icon that displays the following options: Download—Copies the graph to your default download directory as a PDF, CSV, or Image (PNG) file. Add To Quickviews—Creates a customized Monitor page that includes graphs that you add with this option. The page is located at Insights > Quickviews and is described in  Create and manage Quickviews . Display options that control the data presentation. The left option is displayed by default when the page or data is loaded. The option displayed currently has a white icon on a gray background. The following four display options are available, though not all graphs include all options: Bubble—Displays a different sized circle for each data component. Larger circles represent more traffic. This component is used to represent the volume of data for the traffic statistic being plotted. Click any circle—except those labeled Unknown—to load a page that displays details about the selected statistic. Unknown components are those that have been configured in the past, and have been deleted since then. They have no associated details. Line—Displays two or more data points, with adjacent data points connected by a straight line. This component is used to represent the volume of data per second for the traffic statistic being plotted. Line graphs are also know as time series graphs. Click a category in the legend to hide or show the corresponding line in the graph. At least one category must remain selected. Hidden categories are represented by a white outlined box, and displayed categories use a solid color. Hover over the graph to display the value of each statistic plotted on the graph at the corresponding time. Click, drag, and release to select a smaller window of time to display. This custom time selection now applies to all graphs on MyAryaka. After you select a custom time period, it is retained until you click the Reset icon in the filter selector of the page. Table—Displays the data points in rows and columns. This component is used to represent the volume of data for the traffic dimension being plotted. Click any row—except those labeled Unknown—to load a page that displays details about the selected statistic. Unknown components are those that have been configured in the past, and have been deleted since then. They have no associated details. Treemap—Displays a different sized rectangle for each data component. Larger, darker rectangles represent more traffic. This component is used to represent volume of data for the traffic statistic being plotted. Click any rectangle—except those labeled Unknown—to load a page that displays details of the selected statistic. Unknown components are those that have been configured in the past, and have been deleted since then. They have no associated details.  The Data Interval field displays the time period between each sample plotted on the graph. The interval is determined by your selection in the Time drop-down list in the Filter pane. A Load Data button appears on all graphs that do not load data automatically. These graphs do not load automatically because they slow the overall page load time. Click Load Data to display that graph's data.  Included graphs The sections that follow describe each of the graphs included on the top-level SD-WAN > Monitor page. WAN Traffic The primary graph that plots the total WAN traffic for the selected site, traffic direction, and time period.  WAN Traffic by Provider This graph offers three display options: the default bubble graph and the table each show the  volume  of data for each of your internet service providers (ISPs), MPLS providers, and direct internet access (DIA) providers for the selected site, traffic direction, and time period, and the time series line graph shows the  rate  of data for each provider and plots the following  two  data points for each of your providers: <ISPname>— Plots the actual usage for this provider. <ISPname>  size—Plots the link size. Unless the link size changes during the selected time period, this appears as a horizontal line. In the bubble graph or table view, click an ISP to view the Provider Traffic: < ISPname > page. This page displays graphs of total provider traffic, traffic by network, and traffic by application.  Note: The color-coded squares in the legend of the line graph can appear with no text labels depending on the size of your display. Click the Expand icon to display the graph using the full width of your display to view the labels. This graph can include an  Unknown  provider if an ISP that existed the selected site's configuration in the past and has since been deleted. ISPs are configured on the Sites >  siteName page .  MPLS providers are configured by  contacting customer support . WAN Traffic by Network This graph offers three display options: the default bubble graph and the table each show the  volume  of data on each network, and the time series line graph shows the  rate  of data on each network. The following networks can appear: VPN Path Aryaka —The Aryaka network that is accessed using secure tunnels that connect your sites using an optimized, private L2 core. VPN Path Internet —The network that establishes tunnels between ANAPs located at each of your sites. These tunnels use the internet to connect your sites and form a backup network to VPN Path Aryaka. Cloud Transport Network Vendor —Sites with ANAPs can connect to a cloud transport network vendor, for example,  Microsoft Azure Virtual WAN . Cloud Security Vendors —Sites with ANAPs can connect to a  supported cloud security vendor , for example, Check Point Harmony Connect or Zscaler. Direct Internet —Sites with ANAPs can send traffic directly to the internet after NAT is applied to it.  MPLS Vendors—Sites with ANAPs can connect to an MPLS CE and exchange routing information with it to route traffic over MPLS based on the routes learned. Click the links above to view the associated monitor topics for the network. This graph can include an  Unknown  network if a network existed the selected site's configuration in the past and has since been deleted. In the bubble graph or table view, click a network to view the Network: < networkName > page. This page displays graphs for the selected network, such as the total network traffic, traffic by provider, and traffic by application. WAN Traffic by Remote Site This graph offers two display options: the default treemap graph and a table that each display the volume of data for each remote site connected to the selected reference site.  Remote sites include your sites with one of the following license types: Global, Regional, IaaS, or SmartConnect EZ. Your reference site may connect to your remote site using VPN Path Aryaka or VPN Path Internet. Note: Aryaka does  not  monitor site-pair traffic for sites that connect using an MPLS network. This graph can include an  Unknown  treemap box if a site existed in your topology in the past and has since been deleted. In either graph view, click a remote site to view the Remote Site: < siteName > page. This page displays graphs of total remote site traffic and traffic by network.  WAN Traffic by App Group This graph offers two display options: the default treemap graph and a table that each display the volume of data for each configured application group. An application group is a user-defined collection of associated applications. Application groups be can be created for any number of reasons, including tracking statistics of a collection of applications or to simplify the management of applications with similar security, routing, or optimization configurations. This graph can include an  Unknown  treemap box if an application group existed in the past and has since been deleted. In either graph view, click an application group to view the App Group: < groupName > page. This page displays graphs of total app group traffic, traffic by application, and traffic by network.  WAN Traffic by Application This graph offers two display options: a treemap graph and a table that each display the  volume  of data for each user-defined or discovered application. A site's traffic can be categorized into the three following types: Traffic that includes applications that are discovered using Aryaka's Deep Packet Inspection. Traffic that includes applications that are identified by user-defined configuration. After initial identification, this traffic may then use Aryaka's Deep Packet Inspection, manually listed domains, or IP address and port-based matching. Unknown traffic that could not be discovered by Deep Pack Inspection or was previously tagged as user-defined application traffic that has been deleted since the statistic was collected. In either graph view, click an application to view the Application: < applicationName > page. This page displays graphs of total application traffic and traffic by network.  WAN Traffic by Zone This graph requires you to click Load Data to display WAN traffic data. It offers three display options: the default bubble graph and the table each display the  volume  of data on each WAN zone, and the time series line graph displays the  rate  of data on each WAN zone. A zone is typically a LAN-side construct, but you can use the Aryaka network to connect sites that share the same zones. This zone information is preserved across Aryaka's core to provide network segmentation functionality. Note that this is only applicable for VPN zone types, and requires a site's VPN zone to have both a LAN context and a WAN context. In the bubble graph or table view, click a zone to view the WAN Zone: < zoneName > page. This page displays graphs of total WAN zone traffic, traffic by application group, and traffic by application. Note: In the case where your site is a hub site for flows coming from a remote site and going to another, traffic never goes to the site's LAN zone. This traffic is displayed in a bubble named Transit Traffic and  cannot  be clicked to display details. This graph can include an  Unknown  WAN zone bubble if a zone existed in the site's configuration in the past and has since been deleted.  LAN Traffic by Zone This graph appears next to the WAN Traffic by Zone graph to allow you to perform a side-by-side comparison of a zone's traffic on the selected site's LAN and WAN. It requires you to click Load Data to display LAN traffic data. It offers three display options: the default bubble graph and the table display the  volume  of data on each LAN zone and the time series line graph shows the  rate  of data for each LAN zone. In the bubble graph or table view, click a zone to view the LAN Zone: < zoneName > page. This page displays graphs of total LAN zone traffic and total WAN zone traffic. See the  Monitor LAN zone traffic  topic for details on this page.  Note: In addition to the traffic that travels from the LAN to the WAN, and the traffic that travels from the WAN to the LAN, there can also be zone-to-zone local traffic to the site that is also included in the LAN Traffic by Zone graph's statistics.  This graph can include an  Unknown  LAN zone bubble if a zone existed in the site's configuration in the past and has since been deleted. Quicklink toolbar The Quicklink toolbar is the black menu that appears floating at the bottom of the page. It contains a Show Details icon that displays a text label for each of the icons included. The Quicklink toolbar is context sensitive, so the icons only appear if the feature is implemented in your Aryaka network or is relevant to the traffic statistic you are currently viewing. For example, the top-level SD-WAN > Monitor page has a Quicklink toolbar that contains links for ANAPs, flow logs, and top talkers. If you navigate from there to Site > VPN Path Aryaka, the toolbar now displays the following options: Health, Link Assure, Compression, QoS, TCP Optimization, SMB, SSL, and Flow Logs.  In this topic Related topics SD-WAN flow logs Monitor a site's top talkers Monitor VPN Path Aryaka Monitor VPN Path Internet Related video Analyze a site's WAN traffic