On NetEye we are using NfSen for the collection, analysis and view of NetFlow data.
Unfortunately, many users complain, that the NfSen tool is not that simple to use, especially in terms of fast data analysis and for the reporting of the analysis results to their responsibles.
NfSen is able to provide many possibilities to analyze NetFlow data, but if you need an easy standard view for the most important data flow scenarios, it is maybe better to use Kibana4 for visualizing this data.
Kibana4 is integrated to NetEye 3.6. Thanks to the use of Logstash and Elasticsearch it is possible to gather the NetFlow data for creating clear Kibana4 dashboards.
On the following four images you can see four visualization examples for NetFlow data on Kibana4. Obviously, you can easily filter this information for a time period, which can be individually selected from the GUI.
Here you can see the top 10 source ports, which are creating the most traffic.
Here you can see the top 10 destination ports, which are creating the most traffic.
Here you can see the top 10 source IP’s, which are creating the most traffic
Here you can see the top 10 destination IP’s, which are creating the most traffic.
I started my professional career as a system administrator.
Over the years, my area of responsibility changed from administrative work to the architectural planning of systems.
During my activities at Würth Phoenix, the focus of my area of responsibility changed to the installation and consulting of the IT system management solution WÜRTHPHOENIX NetEye.
In the meantime, I take care of the implementation and planning of customer projects in the area of our unified monitoring solution.
Author
Tobias Goller
I started my professional career as a system administrator.
Over the years, my area of responsibility changed from administrative work to the architectural planning of systems.
During my activities at Würth Phoenix, the focus of my area of responsibility changed to the installation and consulting of the IT system management solution WÜRTHPHOENIX NetEye.
In the meantime, I take care of the implementation and planning of customer projects in the area of our unified monitoring solution.
In order to be able to carry out detailed network monitoring, an IT administrator naturally wants to know what is happening in his or her network. To obtain this information, the network flows must of course be analyzed. Many network Read More
First of all, I'd like to explain in simple terms what Elastiflow is all about. ElastiFlow is a NetFlow analyzer that works with the Elastic Stack. The Elastiflow Analyzer can collect various network flows, such as netflow or sflow, and Read More
Keeping historical data around for analysis is extremely useful but often avoided due to the financial cost of archiving massive amounts of data. Retention periods are thus driven by financial realities rather than by the usefulness of extensive historical data. Read More
Some time ago I was able to use the machine learning functionality in Elastic for the first time. I was astonished at how easy it is to use, and how fast it calculates historical data. In my particular case, I Read More
With the idea to get out more from the netflow data fetched by Nfdump and with special needs of our customers, we added some new and useful functionalities to make Nfdump even more interesting and useful for your network traffic Read More