Full width image
NetFlow / sFlow


Mainly used to collect IP traffic information for network traffic monitoring and analysis.
After enabling the NetFlow function on the Client-side devices (such as routers or switches),
these devices will regularly generate network traffic reports (called "flow records" or "flow data") and provide the following information:

➢ Source and destination of network traffic
➢ Size of the traffic
➢ Type of data transmission protocol used (such as TCP or UDP)
➢ Start and end time of the data flow

If the client's device has enabled the NetFlow function,
the WATCHDOG system can interface with it to analyze and visualize the NetFlow data.
In this process, the client's device needs to direct the NetFlow data to the WATCHDOG host.
And convert this data into easily understandable reports and visual interfaces for administrators to view and analyze.


System Specifications for Monitoring NetFlow and sFlow
The WATCHDOG system interfaces with NetFlow / sFlow to grasp network data flow in real-time by providing detailed information for each data packet,
including important information for various network communications, to achieve network security and performance optimization.

➢ Detection purpose: Achieve real-time monitoring of network traffic,
including source IP, communication ports, MAC address, and detailed information of protocols like ICMP, IGMP, TCP, UDP, ARP, etc.
➢ Monitoring targets: Capture all network traffic recorded by NetFlow and sFlow protocols
➢ Alarm conditions: Set up an alarm mechanism based on hourly statistics, and real-time publication of data and alarms
➢ Information collection: Centrally collect messages, data, and the publication and cancellation times of alarms, ensuring the timeliness and accuracy of information
➢ Emergency handling: Upon detecting abnormalities, immediately notify and execute predefined emergency procedures to ensure network security
➢ Alarm threshold: Define and adjust alarm thresholds based on different application needs


Traffic Record Function
The WATCHDOG system has a traffic recording function designed to support devices such as routers, firewalls, and core switches that support NetFlow and sFlow protocols.
By collecting and analyzing the network traffic data from these devices, WATCHDOG can provide statistics, analysis, and tracking bases to help users achieve more effective network management. With our national domain database containing over 3.6 billion entries, we can instantly provide the country of origin information for any IP, enabling us to immediately identify the country of origin for any IP address.


※Special Note
The functions of NetFlow and sFlow are the same, and although the data content may differ, the WATCHDOG system will strive to make them consistent.



Back to the previous page