NETFLOW / IPFIX TRAFFIC OBSERVABILITY

NetFlow Monitoring and Realtime Traffic Analytics

Flowtrion centrally collects NetFlow v5, NetFlow v9 and IPFIX records and turns them into source/destination IP, port, protocol, subnet, interface, ASN, Mbps/Gbps and PPS visibility. ISP, data center and enterprise NOC teams can understand traffic through flow context instead of relying on aggregate bandwidth alone.

NetFlow v5 / v9 / IPFIXFlow formats
Bps + PPSBidirectional traffic
IP / Port / ASNOperational context
Historical + liveOne investigation flow
01 / NetFlow Monitoring

What is NetFlow monitoring?

NetFlow monitoring collects and analyzes flow records exported by routers, switches and firewalls. A flow is commonly identified by a five-tuple: source IP, destination IP, source port, destination port and IP protocol. Depending on the exporter, a record may also include byte and packet counters, timestamps, ingress and egress interfaces, TCP flags, ToS/DSCP and ASN data. This goes beyond the SNMP question “how busy is the interface?” and answers who communicated with whom, over which service, in which direction and at what time.

FLOWTRION

NetFlow monitoring capabilities in Flowtrion

From collector ingestion to the operations screen, telemetry is evaluated together with traffic, security and routing context.

Realtime traffic

Track inbound and outbound traffic on the same timeline using Mbps/Gbps and PPS, without hiding packet-rate anomalies inside bandwidth totals.

IP and top talker analytics

Rank the busiest sources, destinations and IP pairs to identify heavy clients, servers, subscribers or unexpected communication patterns.

Subnet and interface visibility

Group traffic by subnet, exporter and interface to evaluate capacity changes and routing shifts in the correct operational context.

Port and protocol analytics

Inspect TCP/UDP ports, service behavior and protocol distribution to surface unexpected application usage.

Historical investigation

Compare traffic before and after an event and investigate with retained evidence instead of relying on a momentary alert.

Anomaly and DDoS signals

Interpret deviations in Bps, PPS, target concentration, protocol mix and source distribution against a normal baseline.

COLLECTOR PIPELINE

How does a NetFlow collector work?

The network device converts observed traffic into flow records and exports them to the Flowtrion collector over UDP. NetFlow v9 and IPFIX are template-based, so the collector decodes template records before processing the associated data sets. A normalization layer maps multi-vendor fields into one traffic model; the analytics layer then provides live dashboards, historical queries, top talker rankings and security signals.

1

Exporter

A router, switch or firewall creates flow records.

2

Collector

NetFlow/IPFIX datagrams and templates are decoded.

3

Normalize

Device, interface, subnet and ASN context is added.

4

Analyze

Dashboards, history, alerts and investigations become available.

TELEMETRY MODEL

Supported NetFlow and IPFIX formats

NetFlow v5

A widely deployed fixed-record format that remains useful for IPv4 flow visibility across legacy and current network devices.

NetFlow v9

A template-based format where the exporter describes the structure of its records, enabling richer fields based on platform capabilities.

IPFIX

An open IETF flow-export standard built around extensible information elements, with flexibility for IPv4, IPv6 and vendor-specific data.

DATA FIELDS

Which traffic fields can NetFlow analyze?

  • Source and destination IP addresses
  • Source and destination TCP/UDP ports
  • IP protocol and TCP flags
  • Bytes, packets, Bps and PPS
  • First/last seen time and flow duration
  • Ingress and egress interfaces
  • Subnet, VLAN and direction context
  • Source/destination ASN and next hop
  • DSCP/ToS and traffic class
  • Exporter, observation domain and sampling metadata
OPERATIONAL OUTCOMES

NetFlow traffic analytics use cases

DDoS detection

Correlate destination concentration, source diversity, protocol behavior, Mbps and PPS changes against a normal baseline.

Top talker analysis

Compare the largest IPs, subnets, protocols and services by bandwidth or packet rate across different time ranges.

Capacity planning

Measure busy hours across transit, peering, uplink and customer networks to make evidence-based growth decisions.

Incident investigation

Review communication pairs, port changes and traffic direction before and after an alert.

Outbound spam visibility

Investigate sources contacting unusually large numbers of SMTP destinations and short-lived connection patterns.

BGP operations context

Evaluate traffic changes together with ASN, subnet and routing policy context before taking controlled action.

DEPLOYMENT GUIDE

How should a NetFlow exporter connection be planned?

Commands vary by vendor, platform and software release. A reliable rollout validates not only the collector address but also the export source, observation domain, template refresh behavior, active/inactive timeouts and sampling metadata.

Juniper Junos

Create a sampling instance and an IPFIX or v9 template, define the flow-server address, UDP port and source address, then bind the correct family and interfaces. Confirm support for the exact MX, PTX, QFX, EX or SRX model and Junos release.

Cisco IOS / IOS-XE

With Flexible NetFlow, define a flow record, flow exporter and flow monitor, then apply the monitor to the required interfaces and direction. Verify exporter source and template timeout settings.

MikroTik RouterOS

Enable Traffic Flow, select the interface scope and create a collector target using NetFlow v5/v9 or IPFIX. Consider NAT behavior and interface naming during interpretation.

Fortinet / Huawei / Arista

Enable the platform-specific NetFlow, NetStream or IPFIX export feature. Validate exported fields, sampling ratio and template delivery at the collector.

Production recommendation: begin with one device and a limited set of interfaces. Verify export datagrams, template records, clock synchronization and sampling metadata before expanding the scope.

DECISION FRAMEWORK

NetFlow vs sFlow, SNMP and port mirroring

TechnologyData typeBest suited for
NetFlow / IPFIXFlow metadata and countersLarge-scale analysis by IP, port, protocol, interface and time
sFlowSampled packet headers + interface countersStatistical visibility in high-speed, high-port-density networks
SNMPInterface and device countersHealth, capacity and aggregate usage; limited talker and port context
SPAN / Port MirroringCopied packet trafficDeep packet analysis and forensics with higher bandwidth and storage cost
FAQ

NetFlow monitoring FAQ

What is NetFlow monitoring?

NetFlow monitoring collects records exported by routers, switches and firewalls, then analyzes traffic by source, destination, port, protocol, interface, packets and bytes.

Which flow formats does Flowtrion support?

Flowtrion processes NetFlow v5, template-based NetFlow v9 and the open IPFIX standard, subject to the information elements exported by the device.

Does NetFlow contain packet payloads?

Typically no. NetFlow and IPFIX export traffic metadata and counters rather than full payloads. SPAN or TAP-based methods can be evaluated when deep packet content is required.

Can NetFlow help detect DDoS attacks?

Yes. Sudden changes in Bps, PPS, destination concentration, port and protocol behavior provide strong DDoS indicators when compared with a normal baseline.

FLOWTRION NETWORK INTELLIGENCE

Turn NetFlow telemetry into operational decisions.

Let us evaluate your exporters, traffic volume, retention requirements and NOC/SOC investigation workflow together.

Schedule a technical consultation
TECHNICAL RESOURCES

Continue with related implementation guides