NetFlow Realtime tool
The NetFlow Realtime tool in ETS for the Desktop provides a granular view of your network traffic. You can see the most recent 5 to 60 minutes of flow data broken out by applications, conversation, domains, endpoints, and protocols. You can use NetFlow Realtime to explore exactly how your bandwidth is being used and who is using it.
Open the NetFlow Realtime tool
-
To launch the tool from the Toolset Launch Pad, locate the NetFlow Realtime tool and click Launch.
-
You can add the tool to a tab in the Workspace Studio, and access it from there.
-
To launch the tool from the Windows Start menu:
-
Click Start > All > SolarWinds Engineer's Toolset.
-
Right-click NetFlow Realtime, click More, and click Run as administrator.
-
Capture NetFlow data
Before you can begin analyzing data exported by your NetFlow-enabled routers and switches, you must capture the flows. Complete the following tasks before you attempt to monitor data with NetFlow Realtime.
Prepare to capture data
-
Modify the configuration of your NetFlow device to ensure it is exporting NetFlow data.
Due to the large number of different routers and switches that can export NetFlow data, consult your Cisco device documentation for instructions to enable NetFlow data export. A technical reference is available on the SolarWinds website. For more information, see Enable NetFlow and NetFlow Data Export on Cisco Catalyst Switches.
-
Ensure you know the listening port for NetFlow data.
This port is part of the configuration of the NetFlow device.
-
Ensure you know the IP address or host name of the NetFlow device.
-
Ensure you know the community string or SNMP version 3 credentials.
Capture data
-
In the Listen on port field, specify the listening port for exported NetFlow data.
-
Click Add NetFlow Device
, and then specify the following information on the NetFlow Device Credentials window.- IP address or host name of the NetFlow device
- Community string or SNMPv3 credentials.
-
Click Test, and then review the Credentials Test window.
-
Make any necessary adjustments to your values on the NetFlow Device Credentials window, and then click OK.
If NetFlow Realtime is able to communicate with NetFlow data, a green check mark is displayed in the Sending NetFlow column of the NetFlow Analyzer user interface.
Store NetFlow data
NetFlow Realtime stores up to 60 minutes of captured NetFlow data in Microsoft Access-readable capture files. You can modify the location of capture files by changing the path displayed in the Capture file field of the NetFlow Realtime user interface.
Analyze NetFlow data
NetFlow Realtime offers up to 60 minutes of traffic to analyze. See the following groups.
| Applications |
Applications enable you to see all the traffic passing through based on the application. Applications use specific ports to send data. This mapping between port, application, and traffic is used to create the specific data points. The number of applications listed in the tree changes based on the Top XX value. Click the top node, Applications, to view an inclusive graph.
|
| Conversations |
Enables you to see traffic based on source and destination IP address, source and destination port, and the protocol. These five data points, grouped together and matched, create a single conversation. For example, a conversation between 1.1.10.10 and google.com is defined by 1.1.10.10, google.com, port 80 (HTTP) on both IP addresses, and the TCP protocol.
|
| Domains | Enables you to see all traffic in a domain. The domain consists of all resolveable IP addresses using reverse DNS, to that domain. Clicking a domain or IP address in the tree provides a view of all the other domains or IP addresses with which this domain is in communication. Clicking the top node, Domains, provides an inclusive graph of all the domains on which traffic is being detected. |
| Endpoints |
Allows you to select specific IP addresses (hosts) and view all the data transmitted and received by that host.
|
| Protocols |
Displays all the traffic that matches a specific protocol, for example, TCP or UDP.
|
Start Flow capture
-
Click the interface through which NetFlow data is flowing to analyze, and then click Start Flow Capture.
-
Review the information displayed in the analysis graphs.
-
The tree view can be expanded to reveal individual applications, conversations, domains, endpoints, and protocols. Tree views are dynamic; changing based on time period and the selected Top ## number.
-
The refresh rate is in seconds.
Define applications and modify port definitions
NetFlow Realtime uses the port assigned to an application to define the application.
-
Click the NetFlow data interface to analyze, and then click Start Flow Capture.
-
Click Tools > Application Mappings.
-
To add a new Application definition:
-
Click Add Application
. -
Provide the information on the Add new window, and then click OK.
-
Ensure the spreadsheet of applications, protocols, and ports is correct, and then click OK.
-
-
To edit the definition of a port or Application:
-
Click Edit Application
. -
Modify the fields on the Edit window, and then click OK.
-
Ensure the spreadsheet of applications, protocols, and ports is correct, and then click OK.
-