Realtime traffic
Track inbound and outbound traffic on the same timeline using Mbps/Gbps and PPS, without hiding packet-rate anomalies inside bandwidth totals.
Flowtrion centrally collects NetFlow v5, NetFlow v9 and IPFIX records and turns them into source/destination IP, port, protocol, subnet, interface, ASN, Mbps/Gbps and PPS visibility. ISP, data center and enterprise NOC teams can understand traffic through flow context instead of relying on aggregate bandwidth alone.
NetFlow monitoring collects and analyzes flow records exported by routers, switches and firewalls. A flow is commonly identified by a five-tuple: source IP, destination IP, source port, destination port and IP protocol. Depending on the exporter, a record may also include byte and packet counters, timestamps, ingress and egress interfaces, TCP flags, ToS/DSCP and ASN data. This goes beyond the SNMP question “how busy is the interface?” and answers who communicated with whom, over which service, in which direction and at what time.
From collector ingestion to the operations screen, telemetry is evaluated together with traffic, security and routing context.
Track inbound and outbound traffic on the same timeline using Mbps/Gbps and PPS, without hiding packet-rate anomalies inside bandwidth totals.
Rank the busiest sources, destinations and IP pairs to identify heavy clients, servers, subscribers or unexpected communication patterns.
Group traffic by subnet, exporter and interface to evaluate capacity changes and routing shifts in the correct operational context.
Inspect TCP/UDP ports, service behavior and protocol distribution to surface unexpected application usage.
Compare traffic before and after an event and investigate with retained evidence instead of relying on a momentary alert.
Interpret deviations in Bps, PPS, target concentration, protocol mix and source distribution against a normal baseline.
The network device converts observed traffic into flow records and exports them to the Flowtrion collector over UDP. NetFlow v9 and IPFIX are template-based, so the collector decodes template records before processing the associated data sets. A normalization layer maps multi-vendor fields into one traffic model; the analytics layer then provides live dashboards, historical queries, top talker rankings and security signals.
A router, switch or firewall creates flow records.
NetFlow/IPFIX datagrams and templates are decoded.
Device, interface, subnet and ASN context is added.
Dashboards, history, alerts and investigations become available.
A widely deployed fixed-record format that remains useful for IPv4 flow visibility across legacy and current network devices.
A template-based format where the exporter describes the structure of its records, enabling richer fields based on platform capabilities.
An open IETF flow-export standard built around extensible information elements, with flexibility for IPv4, IPv6 and vendor-specific data.
Correlate destination concentration, source diversity, protocol behavior, Mbps and PPS changes against a normal baseline.
Compare the largest IPs, subnets, protocols and services by bandwidth or packet rate across different time ranges.
Measure busy hours across transit, peering, uplink and customer networks to make evidence-based growth decisions.
Review communication pairs, port changes and traffic direction before and after an alert.
Investigate sources contacting unusually large numbers of SMTP destinations and short-lived connection patterns.
Evaluate traffic changes together with ASN, subnet and routing policy context before taking controlled action.
Commands vary by vendor, platform and software release. A reliable rollout validates not only the collector address but also the export source, observation domain, template refresh behavior, active/inactive timeouts and sampling metadata.
Create a sampling instance and an IPFIX or v9 template, define the flow-server address, UDP port and source address, then bind the correct family and interfaces. Confirm support for the exact MX, PTX, QFX, EX or SRX model and Junos release.
With Flexible NetFlow, define a flow record, flow exporter and flow monitor, then apply the monitor to the required interfaces and direction. Verify exporter source and template timeout settings.
Enable Traffic Flow, select the interface scope and create a collector target using NetFlow v5/v9 or IPFIX. Consider NAT behavior and interface naming during interpretation.
Enable the platform-specific NetFlow, NetStream or IPFIX export feature. Validate exported fields, sampling ratio and template delivery at the collector.
Production recommendation: begin with one device and a limited set of interfaces. Verify export datagrams, template records, clock synchronization and sampling metadata before expanding the scope.
| Technology | Data type | Best suited for |
|---|---|---|
| NetFlow / IPFIX | Flow metadata and counters | Large-scale analysis by IP, port, protocol, interface and time |
| sFlow | Sampled packet headers + interface counters | Statistical visibility in high-speed, high-port-density networks |
| SNMP | Interface and device counters | Health, capacity and aggregate usage; limited talker and port context |
| SPAN / Port Mirroring | Copied packet traffic | Deep packet analysis and forensics with higher bandwidth and storage cost |
Explore sFlow monitoring when you need sampled packet headers and interface counters across high-port-density environments.
NetFlow monitoring collects records exported by routers, switches and firewalls, then analyzes traffic by source, destination, port, protocol, interface, packets and bytes.
Flowtrion processes NetFlow v5, template-based NetFlow v9 and the open IPFIX standard, subject to the information elements exported by the device.
Typically no. NetFlow and IPFIX export traffic metadata and counters rather than full payloads. SPAN or TAP-based methods can be evaluated when deep packet content is required.
Yes. Sudden changes in Bps, PPS, destination concentration, port and protocol behavior provide strong DDoS indicators when compared with a normal baseline.
Let us evaluate your exporters, traffic volume, retention requirements and NOC/SOC investigation workflow together.