You can detect suspicious traffic events, such as abnormal network traffic activity and malicious behavior, across your NSX environment using the NSX Suspicious Traffic feature in Security Intelligence. The Suspicious Traffic feature is available with Network Detection and Response (NDR) even when the Security Intelligence feature is not enabled.

Use the information in this section to start using the NSX Suspicious Traffic feature, analyzing events, and managing the NSX Suspicious Traffic detector definitions.