NetFlow Collector
Collect network traffic with a NetFlow collector
SolarWinds® NetFlow Traffic Analyzer (NTA) uses flow-based monitoring to collect and analyze flow data from multiple Cisco vendors, including NetFlow v5 and v9, Juniper J-Flow, sFlow, Huawei NetStream, and IPFIX. NTA’s flow navigator can allow you to create and access personalized network traffic views, while the reporting system enables you to create in-depth network traffic reports and schedule automatic weekly delivery to your team with a few clicks.
Correlate NetFlow collector data and unveil traffic patterns with cross-stack metrics
Whether examining network interface utilization, application performance counters, VM host memory utilization, database wait metrics, or storage IOPS, the available SolarWinds Perfstack™ feature gives you the ability to compare these data types alongside NetFlow analytics from NTA. You can use the PerfStack dashboard for easier performance analysis and to accelerate the identification of root causes by dragging and dropping network performance metrics on a common timeline for immediate visual correlation across your network data.
Pinpoint the cause of network bottlenecks
NetFlow capture tools help you evaluate bandwidth usage by application, so you can discover which specific users and applications are responsible for consuming the most bandwidth and creating bottlenecks. You can adjust your alerts in NTA to target specific top talkers on your network, and you can use this information to minimize the impact of their usage over time.
NTA is built to allow you to track application traffic arriving from designated ports, source IPs, and destination IPs, and even analyze network protocols. Understanding bandwidth usage by assigning IP groups, which can allow you to better characterize and analyze NetFlow data received.
Easily analyze NetFlow collector data
NTA is a network collector designed to gather flow data from your full range of networked devices, which can then be more easily analyzed for deeper insights. In the dashboard, you can quickly drill down, filter, and navigate through granular analytics—for everything from which applications and users are hogging the most bandwidth to system-wide traffic patterns.
Get More on NetFlow Collector
What is a NetFlow collector?
NetFlow is a protocol developed by Cisco Systems used to record statistical, infrastructure, routing, and other information about traffic flows passing through a NetFlow-enabled router or switch. A NetFlow collector is part of a flow monitoring system designed to receive, process, and store IP traffic data packets from these network devices.
Once the data has been properly formatted, NetFlow collectors forward the data to another application for analysis. Analyzing NetFlow data can reveal valuable insights into infrastructure, routing, and performance, but requires three primary tools, one of which is a flow collector. These tools are:
- NetFlow exporter: A NetFlow-enabled device generating flow records containing information about IP traffic and exports these flow records to a flow collector
- NetFlow collector: Receives flow records from the various exporters, then processes and stores the data for analysis
- NetFlow analyzer: Translates flow data into charts, graphs, tables, and other visualizations providing an at-a-glance understanding of network status and performance
In distributed or high-traffic networked environments, flow collectors can be likewise distributed for more comprehensive data collection, but each of the collectors will need to be configured to send the data to a centralized server for analysis.
How does a NetFlow collector work?
NetFlow collectors receive IP traffic packets from one or more NetFlow-enabled export devices, then ingest, pre-process, and store the data before sending it to a NetFlow analyzer. The granular steps involved include:
- Collecting network flow UDP datagrams from the routers and switches with NetFlow enabled
- Translating binary network flow into a textual or numeric format
- Reducing data volume by aggregating, collating, correlating, and selectively filtering flow data
- Saving flow data in easily transmitted files or SQL databases, which is then connected to a NetFlow analyzer application
Why is a NetFlow collector important?
NetFlow collector software plays a critical role in the NetFlow monitoring and analysis process, making it possible for you to gain deeper understandings of network flow, traffic, and bandwidth consumption.
Collecting flow traffic data is the first step to gaining the visibility and actionable insights to allow more effective management of users, applications, devices, and services on a network. NetFlow collectors can also correlate flow data, making them a necessary part of troubleshooting problems related to network traffic across devices. Altogether, this combination of tools and services can help you streamline your network and security monitoring strategies for greater efficiency and effectiveness.
NetFlow collector software is a foundational part of network monitoring strategies, as these tools provide the data used to generate easy-to-understand visualization of top-down views of overall network traffic. This provides network and security teams with insights about which users are the top talkers, which applications are being accessed most frequently, and whether particular end users are hogging an inordinate proportion of network resources.
Understanding NetFlow is also beneficial for capacity planning and scaling network resources to support additional traffic. Upgrading systems and provisioning additional resources can be a significant undertaking, and proper collection and analysis of flow information can provide the empirical data showing the need for additional ports and interfaces capable of sustaining higher bandwidth as demand increases.
NetFlow collection can also contribute to improving network security by enabling teams to more easily detect potential issues. Sudden spikes, drop-offs, and other anomalies in network traffic and flow patterns could be signs of serious security problems like network breaches.
Using NetFlow collector software can also significantly increase the efficiency of network operations. Manually performing NetFlow traffic analysis can be inefficient, requiring more time to produce results with far less accuracy and granular specificity. NetFlow collectors can streamline the process by gathering traffic packets from one or more data sources, and efficiently normalizing and consolidating this information, so it’s organized and usable for analysis. Since network collectors can correlate data metrics by IP address, protocol, or port, this can also enable faster insights into how different network components interact and are affected by flow patterns to help teams pinpoint which devices and services are bottlenecks on the network, in addition to more easily uncovering the root cause of a traffic slowdown.
How does NetFlow collection work in NTA?
SolarWinds NetFlow Traffic Analyzer (NTA) is built to help you examine your network traffic—from a bird’s-eye view and in granular, on-the-ground detail. As multi-vendor, device agnostic NetFlow collection software, NTA gathers a range of traffic data types, including NetFlow v5 and v9 and others, and allows you to quickly alternate between overall views and rapid drill downs on any monitored network component.
NTA is designed to provide down-to-the minute granularity as well as historical records of performance metrics, for insights into how specific events fit into the context of larger traffic patterns. Using Perfstack, you can also accelerate identification of root cause by dragging and dropping NetFlow analytics alongside network performance metrics for quicker visual correlation across network data.
In addition to collecting NetFlow traffic information, NTA provides insight into other useful network metrics. For instance, after collecting information from flow-enabled devices, NTA can help you determine the amount of bandwidth taken up by the conversations between source and destination nodes, which can provide additional context for troubleshooting purposes. NTA also provides flow collection coverage for VMware vSphere switches, which can allow for better traffic filtering and helps minimize the chance of service impacts during workload transitions.
NTA also includes powerful reporting features, which analyzes historical NetFlow traffic data to identify moments of peak usage, top talkers, and other important metrics. This performance analysis can be useful when capacity planning to help you understand when purchasing additional bandwidth may not be necessary because traffic issues could be more efficiently managed through policy adjustments.
Which vendors can NTA collect data from?
NTA supports NetFlow collection for devices from multiple vendors, including Cisco, Extreme Networks, HP, Huawei, Juniper, Nortel Networks, Palo Alto Networks, and others. NTA includes tools for collecting data from different NetFlow traffic types, such as Cisco NBAR2, Huawei NetStream, IPFIX, J-Flow, Juniper, NetFlow v5 and v9, sFlow, and more—including IPFIX traffic from VMware vSwitch virtual devices.
- What is a NetFlow collector?
- How does a NetFlow collector work?
- Why is a NetFlow collector important?
- How does NetFlow collection work in NTA?
- Which vendors can NTA collect data from?
What is a NetFlow collector?
NetFlow is a protocol developed by Cisco Systems used to record statistical, infrastructure, routing, and other information about traffic flows passing through a NetFlow-enabled router or switch. A NetFlow collector is part of a flow monitoring system designed to receive, process, and store IP traffic data packets from these network devices.
Once the data has been properly formatted, NetFlow collectors forward the data to another application for analysis. Analyzing NetFlow data can reveal valuable insights into infrastructure, routing, and performance, but requires three primary tools, one of which is a flow collector. These tools are:
- NetFlow exporter: A NetFlow-enabled device generating flow records containing information about IP traffic and exports these flow records to a flow collector
- NetFlow collector: Receives flow records from the various exporters, then processes and stores the data for analysis
- NetFlow analyzer: Translates flow data into charts, graphs, tables, and other visualizations providing an at-a-glance understanding of network status and performance
In distributed or high-traffic networked environments, flow collectors can be likewise distributed for more comprehensive data collection, but each of the collectors will need to be configured to send the data to a centralized server for analysis.
Get insight into network traffic with a robust NetFlow collector
NetFlow Traffic Analyzer
- Receive alerts when a device stops sending flow data to troubleshoot issues faster
- Collect and analyze flow data from multiple vendors
- Analyze network traffic patterns over months, days, and minutes
Starts at $1,168
NTA, an Orion module, is built on the SolarWinds Platform