INTEGRATED PRODUCT ARCHITECTURE

Eight modules that turn network data into controlled action.

Flowtrion transforms high-volume telemetry into evidence that network teams can use in daily operations. Each module focuses on a specific problem while sharing the same inventory, time and traffic context.

FLOWTRION / MODULE MAPSYSTEM ONLINE
Shared data contextTelemetry · Security · Routing
Realtime
Anomaly
Spoof
SMTP
DNS
BGP
History
Consumers
PRODUCT CAPABILITIES

A specialized workspace for every operational step.

Move from collection and live visibility to event validation, reporting and controlled routing action without manually reconciling separate tools.

TRAFFIC VISIBILITY

Realtime Traffic Analysis

Monitor live inbound and outbound traffic from NetFlow/IPFIX, sFlow and SPAN sources.

Explore module
EVENT VALIDATION

Network Anomaly Detection

Turn meaningful traffic deviations into evidence-rich operational events.

Explore module
SOURCE VALIDATION

IP Spoofing Detection

Identify traffic whose source or destination conflicts with monitored network boundaries.

Explore module
EMAIL SECURITY

SMTP and Spam Detection

Observe port 25 behavior before suspicious systems damage IP reputation.

Explore module
DNS SECURITY

DNS Scan and DNSBL Monitoring

Detect open-resolver exposure and monitor address reputation across selected DNS blocklists.

Explore module
ROUTING OPERATIONS

BGP Management

Manage GoBGP service health, peer sessions, announced networks and community policies centrally.

Explore module
HISTORICAL ANALYTICS

Traffic History and Reports

Compare current conditions with hourly, daily and monthly network behavior.

Explore module
USAGE ANALYTICS

Top Talkers and Bandwidth Analysis

Rank the IP addresses producing or consuming the most traffic in a selected period.

Explore module
FROM TELEMETRY TO DECISION

How Flowtrion modules work together

Flowtrion is designed as a connected investigation environment rather than a collection of isolated dashboards. NetFlow v5, NetFlow v9, IPFIX and sFlow records are normalized into common traffic dimensions such as source, destination, port, protocol, interface, subnet, packet rate and byte volume. When packet-level evidence is required, SPAN, port mirroring or TAP-based tools can complement flow telemetry without changing the operational workflow.

A typical investigation begins with realtime traffic analysis, moves to top talkers to identify the endpoints driving the event, and then uses traffic history to compare the affected interval with normal behavior. Security and routing modules add anomaly, spoofing, DNS, SMTP and BGP context before a response decision is made.

Realtime Traffic Analysis

Monitor inbound and outbound throughput, packet rate, protocols, interfaces and monitored subnets as flow records arrive. Use filters to move from a global traffic change to the source, destination or service responsible for it.

Explore realtime analysis →

Top Talkers and Bandwidth Analysis

Rank sources, destinations and conversations by bytes, packets, protocol, port and subnet. Top-talker views help capacity and security teams explain congestion, bulk transfers, unexpected services and rapidly changing endpoint behavior.

Explore top talkers →

Traffic History and Reports

Search historical NetFlow, IPFIX and sFlow evidence to compare periods, reconstruct an incident and support capacity planning. Reusable time windows and filters make technical findings easier to reproduce and communicate.

Explore traffic history →

Network Anomaly Detection

Compare current volume, packet rate, protocol mix and endpoint distribution with historical behavior. Context-aware investigation helps teams distinguish planned peaks from scanning, abuse, service failure and DDoS indicators.

Explore anomaly detection →

IP Spoofing Detection

Evaluate unexpected source prefixes using traffic direction, interface context and routing expectations. Findings support BCP 38, ACL and uRPF reviews while accounting for NAT, asymmetric routing, anycast and multihoming.

Explore spoofing detection →

SMTP and Spam Detection

Find internal systems creating unusual outbound SMTP connections, destination diversity or packet-rate patterns. Combine network-wide flow evidence with mail-server, endpoint and reputation data before containment.

Explore SMTP monitoring →

DNS and DNSBL Monitoring

Add DNS resolution and configured reputation-list context to suspicious IP, scanner and mail investigations. Lookup results are preserved as supporting evidence and should be evaluated together with observed traffic behavior.

Explore DNS monitoring →
DEPLOYMENT CHECKLIST

Prepare reliable flow telemetry before defining alerts

  • Inventory edge, core, data-center and virtual exporters and document their supported NetFlow, IPFIX or sFlow formats.
  • Synchronize exporter and collector clocks and verify active/inactive flow timeouts, template refresh intervals and sampling rates.
  • Confirm ingress/egress interface mapping, NAT boundaries, duplicate observation points and expected source prefixes.
  • Define retention according to incident investigation, capacity planning, privacy and storage requirements.
  • Observe representative weekday, weekend and maintenance traffic before setting operational baselines.
  • Test BGP or automated mitigation actions in a controlled environment with explicit rollback procedures.

Start with the Flowtrion platform overview, review dedicated NetFlow monitoring and sFlow monitoring guides, or schedule a technical consultation using your exporter inventory and network topology.