The Sophos UTM dashboard has a topic section called "Top Applications". It shows a table of Applications and the Total traffic for each application. Applications include obvious ones like "HTTP" and "SSL". I found an application that caught my notice, and I would like to understand it better. I would prefer not to list it here.
At the moment, all I know is the name of the application, and that its traffic involved several hundred megabytes of data.
Here are my questions:
* How does the UTM determine which application is running for which traffic? Is it as simple as UDP or TCP destination port, or is there more to it? How can I figure out what an application name means or how the UTM defines it? (A simple web search for the application name turned up the incorrect information.)
* Is there a way to drill down to determine which local hosts were running or connecting to that application and when they connected to it?
* Are there logs that show more detailed information? I looked at various logs, but could not find the listed application by name.
This thread was automatically locked due to age.