Netflow

The Netflow module in WOCU-Monitoring allows you to view and analyse network traffic using flow records generated by network devices. The flows contain aggregated information on communications between devices, including:

  • Source/destination IP address

  • Ports used

  • Protocol

  • Traffic volume

  • Connection duration

The Netflow module offers the following features:

  • Network usage analysis

  • Identifying the hosts with the highest traffic usage

  • Detection of anomalous behaviour patterns

  • Research into inter-system communications

  • Visualisation of the geographical origin of traffic

Attention

This makes it possible to analyse network behaviour without having to capture entire packets.

../../_images/2_143_aggregator_realm_netflow_70.png

Access to Netflow

The Netflow module is available via the WOCU-Monitoring interface. Go to the menu: Operation > Netflow. This will display the Kibana-based traffic dashboard, which is natively integrated into the WOCU-Monitoring interface.

../../_images/2_143a_aggregator_realm_netflow_70.png

Note

Access to the Netflow module depends on the user type and the permissions assigned. To request or change access rights, please contact your system administrator.

Use of filters

The panels allow you to apply filters to refine the results displayed. The available filters include:

  • Source/destination IP address

  • Port

  • Protocol

  • Country

  • Autonomous System

  • Export probe

  • Time interval

Filter Bar and Advanced Search

Situada en la cabecera del módulo se encuentran las siguientes opciones de filtrado:

  • Filter and Search bar: allows you to run queries using KQL (Kibana Query Language).

  • Time Range: allows you to define the time window for the data being analysed. You can choose from quick options (Last 1 hour, Last 24 hours, etc.) or set specific time ranges by selecting particular dates and times on the calendar.

Operating Principles

The filters can be combined, which means you can apply several at once to perform more accurate analyses (for example: traffic from a client to a server on a specific service).

When you apply a filter, all the charts in the panel are automatically updated to show only the data that meets the selected criteria, allowing you to move from an overview to a much more detailed analysis in just a few steps.

See the following example in the Overview view, which analyses only the behaviour of the TCP/6350 service reported by the host 127.0.0.1, allowing this traffic to be isolated from the rest of the network for targeted analysis.

../../_images/2_144j_aggregator_realm_netflow_filter_70.png

Best practice

To ensure proactive network management and maximise the benefits of the Netflow module, we recommend incorporating the following procedures into your workflow:

  • Regular review of the Overview dashboard: check the overview daily to familiarise yourself with your network’s performance, making it easier to spot any anomalies straight away

  • Monitor changes in traffic: as a sudden shift in the traffic mix (for example, a sudden increase in UDP compared to TCP) may indicate application failures or attempts to overload the network.

  • Analysing traffic to unusual destinations and eliminating unnecessary traffic flows.

  • Resource monitoring and optimisation: by regularly identifying users or servers that consume the most bandwidth, in order to assess whether it is necessary to redistribute the load across different exporters.