Documentation forNetFlow Traffic Analyzer
Analyzing network traffic and bandwidth is a key capability of SolarWinds Observability Self-Hosted (formerly Hybrid Cloud Observability) and is available in the Advanced edition. NetFlow Traffic Analyzer (NTA) is also available in a standalone module.

Top XX IP Address Groups

This widget provides a view of the IP address groups responsible for the most traffic on your network.

When placed on the Node Details or Interface Details view, this widget provides a view of the IP address groups responsible for the most traffic through the viewed node or interface over the selected period of time.

For more information about IP address groups defined in your NTA, see Selecting IP Address Groups for Monitoring.

There can be two domains for each communication packet processed through a network device, and thus the total traffic counted for IP address groups can seem as much as twice what it is.

View more details about listed IP address groups

Click any listed IP address group to open the NetFlow IP Address Groups Summary view filtered by the appropriate IP address group. For more information, see NetFlow IP Address Groups Summary View.

Click + to expand a listed IP address group and display a list of the nodes and their respective interfaces over which traffic associated with the selected IP address group is currently carried.

Click any expanded node or interface to open the NetFlow IP Address Group view presenting related statistics for the appropriate IP address group. For more information, see NetFlow IP Address Group View.

Top XX IP Address Groups (Endpoint Centric)

You can customize an endpoint-centric version of this widget and place it on the NetFlow Node Details or Interface Details view. The endpoint-centric Top XX IP Address Groups widget provides a ranked list of IP address groups responsible for the most traffic through the viewed node or interface.

For more information about adding endpoint-centric widgets, see Add endpoint-centric widgets to NTA views.

Table legend

The table below the chart provides the following information:

Column Title Contents
Group Displays the IP address group range or name.
Ingress Bytes, Egress Bytes
Ingress Packets, Egress Packets
Displays the amount of traffic in both bytes and packets, through the viewed object traceable to the listed IP address group over the selected period of time.
The columns displayed depend on the flow direction set in the top left corner of the view (either only Ingress Bytes, or only Egress Bytes, or both columns).
Percent (Utilization) Displays the percentage of all traffic over the viewed object that is traceable to the listed IP address group.

The first value describes the percentage of the appropriate item based on items shown by the chart. Individual items in the legend add up 100%. This percentage can be absolute or relative. For more information, see Set the Percentage type for Top XX lists.

A value in parentheses is available only for interfaces. It describes how the appropriate item utilizes the interface bandwidth in percentage.

If the utilization is approximately twice as high as it should be, for example 150% instead of 75%, it might be caused by flow duplication. For more information, see Resolve duplicate flows.

Edit the widget

If you are logged in using a User ID with administrative privileges, you can change the way this widget is displayed for all users:

  1. Click Edit to load the Edit Resource page.
  2. Make changes.
  3. Click Submit.

Edit time and flow direction for the view

You can also change the time period and flows direction shown by all widgets in the view:

  1. Directly below the view name, click next to the appropriate setting and define the appropriate settings.
  2. Change the Relative Time Period, by default set to 1 hour prior to the current time, or specify a specific time period.

The time and flow direction settings are limited to the current session only. After you leave the view, your changes will be lost and default settings are re-applied.