Live traffic visibility
Track inbound/outbound bandwidth and packet rate over time, then evaluate changes in device and subnet context.
Flowtrion processes sampled packet headers and periodic interface counters exported by sFlow agents. It provides IP, subnet, protocol, top talker, Mbps/Gbps and PPS visibility across high-throughput and high-port-density ISP, data center and enterprise networks.
sFlow is a sampling-oriented telemetry technology designed for high-speed switched and routed networks. An sFlow agent statistically selects eligible packets and exports a defined portion of their Ethernet, IP and transport-layer headers to a collector. It can also report interface byte/packet counters, errors and utilization at a configured polling interval. By combining samples and counters, the collector provides broad visibility into the IPs, services, protocols and subnets producing traffic.
Packet samples and interface counters become traffic and security context on a shared timeline.
Track inbound/outbound bandwidth and packet rate over time, then evaluate changes in device and subnet context.
Identify the busiest sources, destinations, IP pairs and services from sampled traffic.
Correlate polled utilization, packet and error counters with packet samples in the same investigation.
Preserve the exporter sampling rate so operators can distinguish raw observations from estimated total traffic.
Compare peak periods, pre-incident behavior and capacity trends using retained sFlow telemetry.
Investigate deviations in PPS, protocol mix, target concentration and source distribution against normal behavior.
An sFlow agent on a switch or router produces two primary data types: packet samples and counter samples. A packet sample carries a portion of a selected packet header and observation context. A counter sample periodically reports interface statistics. The Flowtrion collector decodes these datagrams, normalizes exporter and interface identifiers, accounts for sampling metadata and turns the result into live and historical traffic analytics.
The device samples packets and reads interface counters.
sFlow datagrams and sample records are decoded.
Sampling, exporter, interface and subnet context is added.
Top talkers, history and anomaly visibility become available.
Can include a portion of Ethernet, IP and transport headers together with ingress interface and sampling metadata.
Periodically report device statistics such as interface bytes, packets, errors, discards and utilization.
On many platforms, sampling occurs in the switching ASIC, supporting high throughput and port density with low additional overhead.
Observe east-west and north-south traffic patterns across high-port-density fabrics using statistical sampling.
Evaluate target concentration, UDP/TCP distribution, source diversity and PPS changes together.
Rank the busiest IPs, subnets, protocols and services while accounting for sampling and time range.
Combine interface counters and traffic samples to track growth across uplinks, leaf/spine and access layers.
Surface new or unusual port and protocol patterns across broad network scope.
Compare Juniper, Arista, Cisco and other supported exporters through a common analytics model.
There is no universal sampling rate. Link speed, packet rate, port count, visibility objectives and collector capacity must be evaluated together. The polling interval controls how often interface counters are reported: shorter intervals create more telemetry, while longer intervals reduce time resolution.
Define the collector address and UDP port, sampling rate and polling interval, then enable sFlow on each required interface. Validate the exact model and Junos release in Feature Explorer.
Configure the sFlow destination, source interface, sampling rate and polling interval, enable sFlow globally and verify the required interface scope.
Enable the platform sFlow feature and configure collector, agent/source, sampling rate and counter polling according to the software release.
Verify sFlow v5 support, sampled header length, interface scope and ingress/egress sampling behavior in platform documentation.
Lower sampling ratios generate more samples but can increase exporter, network and collector load. Start with a rate appropriate for the traffic profile, then tune it using observed sample volume and visibility quality.
| Technology | Data type | Best suited for |
|---|---|---|
| sFlow | Sampled packet headers + interface counters | Statistical traffic visibility at high speed and port density |
| NetFlow / IPFIX | Flow metadata and counters | Detailed analysis by IP, port, protocol, interface and time |
| SNMP | Interface and device counters | Health and aggregate usage; limited talker and port context |
| SPAN / Port Mirroring | Copied packet traffic | Deep packet inspection with higher bandwidth and storage needs |
Explore NetFlow monitoring to analyze NetFlow v5, NetFlow v9 and IPFIX records by IP, port, protocol, ASN and interface context.
sFlow monitoring analyzes sampled packet headers and periodic interface counters exported by an sFlow agent to a collector.
It means the agent statistically samples approximately one packet out of every 1,000 eligible packets. It does not mean every individual flow is observed.
sFlow is sampling-oriented and can include part of a packet header plus interface counters. NetFlow and IPFIX generally export flow records maintained or created by the network device.
Yes. Hardware-assisted statistical sampling makes sFlow useful for broad visibility in high-throughput and high-port-density environments.
Evaluate device scope, link speeds, sampling ratios and retention requirements together with our technical team.