Historical NetFlow Traffic Analysis with Ad-Hoc Filtering and Drill-Down
As a Network Engineer responsible for connectivity across multiple sites, I want PRTG to retain granular flow data (NetFlow/IPFIX/sFlow/jFlow) over configurable historical periods and let me interactively filter, search, and drill down by source/destination IP, port, protocol, interface, and application — without pre-configuring channels — so that I can identify top talkers and traffic anomalies, troubleshoot bandwidth issues retroactively, and deliver trend-based capacity and traffic reports, reducing my mean time to resolution and closing visibility gaps.
With the increasing complexity of enterprise networks, NetFlow has become a standard requirement for network traffic visibility and performance analysis. Many customers now expect the ability to analyze network traffic in depth, identify bandwidth consumers, troubleshoot issues, and generate detailed traffic insights.
Requested Capabilities:
- Native NetFlow monitoring and traffic analysis.
- Historical NetFlow data retention for trend analysis and reporting.
- Advanced filtering based on source/destination IP, ports, protocols, interfaces, applications, and other relevant parameters.
- Interactive dashboards and reports for bandwidth utilization and traffic patterns.
- Support for identifying top talkers, top applications, and traffic anomalies.
- Efficient search and drill-down capabilities for faster troubleshooting.
Business Justification:
- NetFlow is one of the most requested network monitoring features in the current market.
- Customers increasingly expect historical traffic visibility and granular filtering capabilities as part of a modern monitoring solution.
- This enhancement would significantly improve PRTG's network traffic analysis capabilities and strengthen its competitiveness against other enterprise monitoring solutions.
- Based on customer interactions and market feedback, this feature would address a common requirement and deliver substantial value to organizations seeking deeper network insights.
-
lparke@passhe.edu
commented
I need to create automated daily email reports based on sflow data that contain the same info that the sflow sensors do by default: Top Talkers (by IP address), Top connections and Top Protocols (Top Talkers by IP address is the most important). All I can get it to do is top protocols. IP address is not one of the objects. It would be great if these reports included the top talkers by IP info in bar graph form and a "number of talkers to display" field be added.