Ask your network

Telemetry, decoded.

KerbrusFlow Collector

The Dashboard over a one-hour window, showing the Network Overview board: total packets and total traffic against the prior period, top talkers as a bytes-per-minute series with a ranked table of source IPs beneath, source IP networks and Palo Alto App-IDs ranked by bytes, destination AS organisations as a donut, a sankey of traffic between network groups, and destination ports over time.

Decode your network telemetry with a powerful and modern traffic analysis solution.

  • Decode

    One of the widest libraries of vendor-native exports, so the fields your gear already sends arrive with their names still on them.

  • SNMP

    See which devices are up, how hard each link is working and what the hardware is telling you, beside the traffic that explains it.

  • Cloud

    Traffic in your cloud accounts read the same way as traffic on the wire. A path from a user to a workload is one story, end to end.

  • Explore

    Millions of records, one interface. Follow a hunch from a whole network down to a single conversation without writing a query or waiting on a report.

  • Detection

    Know about the slow link or the odd talker before the tickets start. Notice lands where your team already works: SIEM, ticketing, email or chat.

  • Topology

    See how the network is actually wired and which way traffic really goes. A change becomes a decision you can defend.

Your equipment is already describing itself. Most tools throw the description away.

Decode

Get the full value of telemetry you already pay for

Modern exporters send far more than addresses and byte counts. They tell you who the user was, which application it really was, and which policy let it through. Flow Collector reads one of the widest libraries of vendor-native exports available, so that detail arrives as something you can rank and act on.

  • Named, not numbered — a vendor field arrives as the thing it describes. A username stays a username all the way through.
  • Nothing to give up at the source — keep the exports your team already tuned. Nothing gets reduced to a common denominator.
A Network Status board on the Dashboard over a one-hour window: a WAN map of sites with the current rate on every link between them, traffic by source over time, destination AS organisation against source group as a chord diagram, a source-to-destination sankey, protocols charted per minute, destination countries ranked by bytes, and applications as a donut totalling 1.0 TB.
A Palo Alto board on the Dashboard over a six-hour window: App-IDs ranked as a donut totalling 495.6 GB, source users listed as named accounts rather than addresses, AWS VPC IDs with their bytes and packets, a sankey running source user to application to App-ID to destination AS organisation, and AWS accept decisions ranked by source group and destination IP.

The link looks fine. The box carrying it has been quietly failing since Tuesday.

SNMP

See the traffic and the box that is carrying it

Traffic tells you what moved. The device tells you whether it can keep moving it. Flow Collector brings both together in one place. A traffic spike and a struggling interface appear on the same screen, so you can see whether they are related.

  • Up, down, and how hard it is working — see reachability and utilization for every device and every port, both over time and right now.
  • One solution for traffic and device health — see NetFlow traffic and SNMP device performance together, without maintaining separate tools for each.
One device in Inventory: acc-nyc1 at 198.18.0.18, up three days and answering all sixty-one of its polls, its twenty-four 10-gig ports and one 8-gig drawn as a block with no errors or discards, the manufacturer, EOS version and sysObjectID it reported over SNMP, which capabilities were detected on it, and the interfaces carrying the highest inbound and outbound utilisation charted over the hour with the WAN circuits they serve named beside them.
The Inventory view over a 24-hour window: fifty-seven devices listed as one roster, each row showing its SNMP state, name and address, vendor, interface count, uptime, whether it is actively exporting flows, its traffic totals, a sparkline and the last poll time.

The complaint crosses your datacentre, your cloud, and the seam between them.

Cloud

Follow the whole path, not the half you own

Workloads moved; visibility mostly did not. Cloud traffic is collected and read exactly like traffic from the wire, so troubleshooting a user's route to an application is one investigation end to end, with nothing assumed in the middle.

  • One investigation, wherever it leads — the same views and filters apply on both sides of the seam, and so does the history.
  • Cloud networks earn their own identity — each one is a place you can name, chart and compare, the way a site is.
Explore over a six-hour window with cloud traffic interrogated exactly the way wire traffic is: a stacked series of the top source IP, AWS VPC, AWS subnet, application and destination IP by bytes, and the ranked table beneath it - ten of 3,663 groups, every one of them PostgreSQL from a single subnet to one destination host, 2.5 GB in all.
The Cloud flow tab of Administration: log ingestion enabled, and one source configured beneath it - an Amazon Web Services VPC flow log bucket for the US region, polling - with the VPC networks found inside it listed alongside, each by its own id.

A link saturated at two in the morning, and nobody can say what filled it.

Explore

Millions of records, and the answer is a few clicks away

The question is rarely the first one you ask. Move from the whole network to a single conversation by following what looks wrong, without writing a query or waiting on someone to build a report.

  • Every answer is the next question — narrow to a moment, a site or a host by pointing at it, and carry the context with you.
  • Slice it the way you think about it — by user, application, country, site or port. Whatever the argument in the room actually needs.
  • And when the rollup runs out — drop into the individual flow records underneath it.
Explore over a 24-hour window, ranked by source IP, application and destination IP, with the menu open on one value in the report: narrow to only this, drop it and rank what is left, regroup by destination port, open the host page, filter to the whole row, explore inside it, or go to the flows behind it - every one of them a next question, and none of them written as a query.
The Flows view over one hour: 14.2 million matching flows and 281.4 GB of them broken down by application, then the raw records themselves - fifty of 14,233,747, each with its exporter, addresses, ports, interfaces, protocol, bytes and TCP flags, a filter box above every column, and one row opened to show its duration, ASNs, countries and the interfaces it entered and left on.

The outage began forty minutes before the first ticket arrived.

Detection

Hear about it before your users do

Performance problems and suspicious behaviour are caught as they happen, and the notice arrives with enough context to act on before you open anything. It reaches your team where they already are — SIEM, ticketing, email or chat.

  • Two kinds of trouble, one watchlist — the saturated link and the host talking somewhere it never has are both worth waking up for.
  • The evidence comes with it — what fired and who was involved, with the evidence behind it. The first minute is spent deciding.
An incident open beside the traffic that caused it: a sharp spike in an Explore chart against a 95th-percentile line, with the incident rail naming it a Traffic Rate Spike, its severity, the host responsible, when it opened, how long it ran, its peak against baseline, and the detection event held as evidence.
The built-in detection rules: seventeen of them listed with the category each belongs to, what each one measures, and the thresholds at which it reports low, medium, high and critical.

The diagram on the wall is three changes and two acquisitions out of date.

Topology

Follow one conversation across the whole network

Your sites and the circuits between them, the devices inside any one of them, and the path a single conversation actually took across both. Enough to plan a change or size a circuit. Or settle the argument about which way traffic really goes.

  • Drawn from the equipment itself — connections and the rates on them come from the devices, and you can follow one conversation hop by hop through every device it crossed, on your own floor and in the cloud alike.
The Topology site map for Acme Global: twenty-five sites drawn as a hierarchy with Ashburn as the hub, cloud regions on the left, Singapore and Frankfurt to the right, and Tokyo, New York and London each carrying five branch sites, every link labelled with what it is currently moving.
One site in Topology: six devices - two core, two distribution, two access - and the links between them, each labelled with its utilisation, above a legend distinguishing links measured at both ends from links mirrored from the near end and links not seen in this window.
A flow report in Explore with the path the traffic took drawn above it: eight devices from acc-nb31 through the New York core and Ashburn to acc-aps1, each segment labelled with the interfaces the traffic entered and left on, and the final hop dashed where the evidence is weaker.

Who this is for

Four kinds of network, one question each

  • Service providers

    Measure transit and peering on your own side at the same 95th percentile you're billed for.

  • Network teams

    The campus and the WAN in one place, with the port-level detail to settle an argument about which application filled a link.

  • Security teams

    Many networks and a lot of traffic. Find a host, and see the conversation it had, down to the individual flow records.

  • Cloud-heavy estates

    The VPCs and transit gateways where the traffic never touches a switch you own, analysed alongside the traffic that does.

Pricing

Point an exporter at it and see what your network has been doing