VOOZH about

URL: https://www.netdata.cloud/features/network/netflow-traffic-analyzer/

⇱ NetFlow Traffic Analyzer | Netdata


πŸ‘ Image

The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring β€” unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

β€” Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

β€” Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexityβ€”real ROI from day one.

β€” Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooksβ€”all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.

Don't Take Our Word for It

From 99% less downtime to 30-second troubleshootingβ€”see how they did it.

Government

Falkland Islands Government

99% less downtime, 30% cloud cost reduction

Transportation

TMB Barcelona

"A rare unicorn that obeys the Pareto rule"

Gaming

Nodecraft

Troubleshooting in 30 seconds, not 3 minutes

Technology

Codyas

46% cost reduction, 67% less monitoring staff

From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

β€” Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

β€” Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

β€” Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

β€” Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

β€” Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

β€” Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 secondsβ€”instant visibility into any node issue.

β€” Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

β€” Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tierβ€”forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever Β· 5 nodes Β· non-commercial
Homelab: $90/yr Β· unlimited nodes Β· fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" β€” LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" β€” Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" β€” Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." β€” TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real dataβ€”no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdataβ€”responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Engineering Insights & Product Updates

Deep dives into monitoring, infrastructure, and what's new in Netdata.

Jun 2026

Network Monitoring, the Netdata Way: …

Interface counters tell you a port is busy. …

Jun 2026

5 Best SolarWinds Alternatives for 2026

As organizations modernize their …

Jun 2026

SolarWinds Price Increases 2026: What …

If you’re a SolarWinds customer facing …

May 2026

High-cardinality metrics at scale: why …

The β€œhigh cardinality is …

Never Fight Fires Alone

Docs, community, and expert helpβ€”pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

Level Up Your Monitoring

Real problems. Real solutions. 112+ guides from basic monitoring to AI observability.

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Nedi Can Help With
Paste Logs & Errors

Trace issues directly in the source code

Deploy & Size Parents

Get architecture recommendations

Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publishβ€”and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automationβ€”GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional servicesβ€”real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" β€” ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alertsβ€”mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

πŸ‘ Image
NetFlow Traffic Analyzer

See Where Your Bandwidth Goes, in Real Time

Ingest NetFlow v5/v7/v9, IPFIX, and sFlow v5 flow records on a single UDP port β€” enriched with GeoIP, ASN, NetBox, and BGP context at the edge. No packet capture, no separate appliance, no metered billing.

πŸ‘ Background
πŸ‘ Hero
πŸ‘ Image

Traffic Intelligence at the Edge

Everything you need to understand who is talking to whom on your network

Real-Time Flow Analysis

Query live flow records over selectable time windows with instant dashboard updates β€” no batch processing or central database round-trips.

Multi-Protocol, One Port

NetFlow v5/v7/v9, IPFIX, and sFlow v5 auto-detected on a single UDP listener β€” no per-protocol configuration or multiple collectors.

Top Talkers and Conversations

Interactive Sankey diagrams and sortable tables rank your top-N flows by bytes or packets, up to 500. Reorder the Sankey columns and add dimensions like TCP flags to see exactly how each conversation is built β€” across up to 10 group-by dimensions.

Geographic Traffic Maps

Country, state, and city-level maps plus a global traffic map visualize flow data enriched with GeoIP coordinates at no extra cost β€” zoom the city map down to street level to pinpoint a specific data center or facility.

Rich Enrichment Built In

GeoIP, ASN, NetBox/IPAM, cloud IP ranges, BGP routing, and classifier-based labeling transform raw IPs into meaningful context at ingest.

No Packet Capture Required

Analyze flow records your devices already export β€” no SPAN ports, TAPs, or packet capture infrastructure to deploy or maintain.

Trusted by network and operations teams worldwide

Flow Analysis That Fits How You Work

Top Talkers, Instantly Visible

Ranked Sankey diagrams and sortable tables show exactly which hosts, ASNs, protocols, or applications consume your bandwidth β€” selectable top-N from 25 to 500, sorted by bytes or packets. Reorder the columns and add dimensions like TCP flags to see precisely how each conversation is structured.

Up to 500 top-N flows

See Network Monitoring

Geographic Traffic at a Glance

Country, state, and city maps enriched by built-in GeoIP show where your traffic originates and terminates β€” zoom the city map all the way down to street level to land on a specific cloud region or data center β€” plus a global traffic map for worldwide visualization.

GeoIP included free

Explore Topology Viewer

Raw IPs Become Meaningful Labels

NetBox/IPAM integration, cloud-provider IP ranges, BGP AS-path and communities, and classifier rules automatically tag every flow with tenant, site, role, and connectivity context.

18 enrichment modules

Browse Flow Integrations

Edge-Native, No Appliance Needed

The Rust-based netflow-plugin runs inside each Netdata Agent β€” decoding, enriching, and storing flow records to disk-backed journal tiers without external collectors or databases.

90+ flow fields tracked

Learn About Agents

Netdata vs. Standalone Flow Analyzers

Why Teams Choose Netdata for Flow Analysis

Built into the same agent that monitors your infrastructure β€” no separate appliance, no metered flow-volume billing, no tool-switching.

Capability

Netdata

Traditional Flow Tools

Architecture
How flows are collected and processed

βœ… Edge-native in-agent
Flows processed where data is generated

⚠️ Separate collector appliance
Dedicated flow collector infrastructure required

Protocol Support
NetFlow, IPFIX, sFlow coverage

βœ… Multi-protocol one port
Auto-detected on single UDP listener

⚠️ Per-protocol or limited
Often requires separate collectors per protocol

Packet Capture
SPAN, TAP, or pcap requirements

βœ… Flow records only
No SPAN ports or packet capture needed

❌ Often requires pcap
Deep packet inspection infrastructure expected

Enrichment
GeoIP, ASN, NetBox, BGP context

βœ… Included at edge
Applied automatically at ingestion time

⚠️ Add-on modules
Extra licensing or manual configuration

Unified Platform
Flows alongside metrics and logs

βœ… Fully unified
Flows, metrics, logs, SNMP in one dashboard

❌ Standalone tool
Separate flow analyzer alongside other tools

Pricing Model
How cost scales with traffic

βœ… Per-node included
No metered flow-volume billing

❌ Volume-metered
Costs increase with flow volume processed

Scalability
How it grows with infrastructure

βœ… Distributed agents
Scale horizontally with Parents and Cloud

⚠️ Central database
Scaling requires bigger central infrastructure

Explore Network Monitoring Solutions

Explore the NetFlow Analyzer

Top Talkers and Conversations

Visualize aggregated flow conversations as interactive Sankey diagrams paired with sortable tables β€” ranked by bytes or packets, selectable top-N from 25 to 500. Reorder the columns and add dimensions like TCP flags to see exactly how each conversation is built.

See who is talking to whom, instantly

View Network Monitoring

Traffic Patterns Over Time

Track top-N flows across selectable time windows with stacked area charts showing bytes per second or packets per second, revealing microbursts and trends.

Catch bandwidth spikes the moment they form

Explore Anomaly Detection

Geographic Traffic Visualization

Country, state, and city-level maps plus a global traffic map render flows enriched with GeoIP coordinates. Zoom the city map all the way down to street level to land on a specific data center or cloud region.

From worldwide down to the street

See Topology Viewer

Interactive Drill-Down

Facet selections with autocomplete, free-text regex search, and up to 10 group-by dimensions let you slice any flow dataset with point-and-click precision.

Find any conversation in seconds

Browse Flow Integrations

Context at Ingestion Time

GeoIP, ASN, NetBox, cloud IP ranges, BGP routing, and classifier rules automatically tag every flow with meaningful labels β€” no post-processing required.

Raw CIDRs become meaningful names automatically

Learn About Agents

Key Takeaways

What makes Netdata flow analysis fundamentally different

Frequently Asked Questions

Netdata ingests NetFlow v5, v7, v9, IPFIX (NetFlow v10 / RFC 7011), and sFlow v5 flow records. All protocols are received on a single UDP listener (default port 2055) with automatic protocol detection from datagram headers β€” no per-protocol configuration required.

No. Netdata analyzes flow records that your network devices already export via NetFlow, IPFIX, or sFlow. There is no deep packet inspection or full packet capture β€” you get the who, what, and where of traffic without deploying any packet-capture infrastructure.

sFlow v5 uses statistical sampling, so byte and packet values in sFlow records are estimates rather than exact counts. Netdata processes sFlow flow samples (counter samples are not surfaced) and presents sampled data with appropriate context. sFlow VLAN information is available from ExtendedSwitch records.

Yes. You can group by up to 10 fields at once, including source/destination IP, port, protocol, ASN, AS name, country, state, city, VLAN, MAC address, BGP AS-path, MPLS labels, interface names, and more. The default grouping is Source AS Name, then Protocol, then Destination AS Name, which drives the Sankey diagram flow direction.

Flow records are stored in four disk-backed journal tiers: raw (full fidelity), 1-minute, 5-minute, and 1-hour rollups. Each tier has independent size and duration limits (defaults: 10 GB and 7 days per tier). Rollup tiers drop high-cardinality fields like raw IPs for compactness, while the raw tier preserves all detail.

Netdata’s ML anomaly detection runs on metrics across the entire platform β€” including network interface metrics and plugin health charts that the netflow-plugin emits. Flow records themselves are stored as journal entries. This means you get ML-powered anomaly detection on your network metrics alongside the flow analysis view, all within the same platform.

Each well-provisioned Netdata Agent handles approximately 50,000 to 100,000 sustained flow records per second. For larger deployments, distribute agents across your infrastructure and aggregate fleet-wide views through Netdata Parents and Netdata Cloud β€” this is the intended distributed architecture, not a workaround.

Packaged installs ship with a stock GeoIP and ASN database seed, providing country, state, city, and ASN enrichment with zero configuration. Additional enrichment modules include NetBox/IPAM integration, AWS/Azure/GCP cloud IP ranges, BGP routing via BMP or BioRIS, rule-based classifiers, static network metadata, and SRv6/VXLAN decapsulation β€” all applied at ingestion time.

June 24, 2026

Network Monitoring, the Netdata Way: Topology, NetFlow, SNMP, and Traps

Netdata has added NPM-class network monitoring: live topology maps, NetFlow and sFlow traffic analysis, SNMP device and trap monitoring, and a dedicated network dashboard, all unified with your full-stack observability and processed at the edge.

September 26, 2023

Netdata QoS Classes monitoring

Ensuring Quality of Service with Advanced Network Insights

June 23, 2026

5 Best SolarWinds Alternatives for 2026

Discover the top SolarWinds alternatives for 2026. Compare modern monitoring platforms built for cloud-native infrastructure - now with NPM-class network monitoring - with transparent pricing and real-time insights.