NetFlow / IPFIX
Use detailed flow relationships for capacity, application and source-destination analysis.
Compare current conditions with hourly, daily and monthly network behavior.
Research IP and subnet traffic by direction and time range, then convert findings into consistent operational reports.
Begin with the global condition, narrow the scope by direction and subnet, identify the responsible source and destination relationship, and compare the result with historical behavior before taking action.
This module uses the same inventory and telemetry model as realtime analytics, security controls, historical reporting and BGP operations.
Use detailed flow relationships for capacity, application and source-destination analysis.
Maintain scalable traffic and PPS visibility across high-speed, high-port-count environments.
Add focused packet-copy visibility for critical services, VLANs and investigation points.
Historical analysis turns a short-lived traffic spike into searchable operational evidence. Flowtrion lets teams compare periods, investigate recurring patterns and preserve context for planning and post-incident reporting.
Stored NetFlow, IPFIX and sFlow measurements provide time-based traffic, packet, endpoint, port, protocol and subnet views. Retention depth and query granularity depend on deployment capacity and the configured data policy.
Teams can compare normal and affected intervals, identify long-term growth and verify whether an event was isolated or recurring. Reports should retain the filters and time zone used so results remain reproducible.
Define hot, warm and archive retention according to investigation needs, storage capacity and privacy requirements. Keep exporter clocks synchronized and document sampling changes that affect comparisons.
Historical views strengthen anomaly tuning, top-talker analysis, SLA review and technical reporting by preserving the context behind a live alert.