NetFlow Auditor provides visibility of every network conversation and scales beyond any other product in the industry.
NetFlow Auditor can perform analysis on any combination of data fields simultaneously (e.g. usage, packets, flows, packet size, utilization, etc) and sort data by any field. Effectively measure usage, trending patterns, baselines, averages, peaks and troughs, and standard deviations.
-
Packet Size analysis - Provides a detailed view of network traffic by packet sizes. Use this information to optimize VoIP traffic as well as to identify packet size anomalies.
-
Count analysis - Count records as part of a result to quickly identify excessive flows or change. Any record combination can be counted, e.g. counting all internal IP's with number of IP or Port conversations enables quick identification of Port Scanners, P2P users, DoS attacks or other multi threaded conversations. Identify long lasting flows or conversations.
-
Deviation analysis - Analyze traffic patterns by standard deviation to identify what aspects have changed the most in a specific period, e.g. knowing what application has changed the most in the last 2 hours can lead to early detection of issues. Identify Worms, increasing flows or data floods.
-
Bi-directional analysis - Show forward and reverse conversations and In vs. Out conversations to quickly identify which side of the conversation is responsible for traffic usage/flows.
-
Comparative Baseline Analysis - Ability to represent multiple variables on a single graphs (subnets, protocols, traffic to endpoint, etc)
-
Baselining analysis - Short term and long term comparative analysis can be performed on any and every element. For example, interface/IP/Location/Application or a combination thereof for a particular period compared against a previous period. Comparative analysis of each element across the time line gives the ability to identify which element caused the change and when. Baseline Alerting can then be activated to learn baselines for every hour for every weekday and alert on anomalies outside thresholds or standard deviations away from the norm.
-
Percentile analysis - Short term and long term percentile analysis can be calculated. For Billing or Security. A percentile analysis of a threshold event will provide an indication of change. This can be set in conjunction with Baseline analysis.
-
Cross section analysis - Stacked graphs enable comparison of any two network traffic parameters. As an example, A stacked bar QoS analysis can graphically show the details of each application running within every class of service.
-
Custom Group analysis - IP addresses can be grouped by Location, Customer, Application and Services. Network traffic detail can now be categorized in logical groups for reporting, billing and capacity planning.
Performance Management versus Forensics
A view to only the "Top" conversations or applications provides sufficient information to quickly troubleshoot the main traffic offenders but most issues hide below the surface. So if deploying only a Top Flow view defeats the purpose of deploying a solution for complete network visibility then why do we sell it?
We know that customers needs are different at different times. By providing a Top Flow view with ability to move to a Full Flow view with a simple license change means that our customers investments are safe. So if budget only allows a small start, we provide the very best small start in the industry.
Many customers entering the NetFlow space are still new and often compare a more competent technique against the lower end collectors in the market place. In this case, our Performance licenses are more appropriate. The collection mechanism in our Performance license offers an low-cost-entry option that still goes deeper in granularity than competitors. NetFlow Auditor Performance license can still handle hundreds of devices. With our Perfomance orientated License the view of data is still highly granular and every effort is made to keep relevant flows with the default but configurable option being split between Top Bytes, Top Packets and Top Flow generators.
The investment benefit with the Performance license is that you can easily move to better visibility or functionality when you are ready without losing your initial investment. Simply by changing or adding to the license key provides increased visibility and add-on features. This means that NetFlow Auditor is a scalable investment that can begin with a small license and grow with changing needs.
Customers say NO to Lack of Granularity when they recognize that it:
 
handcuffs your ability to troubleshoot critical problems and spot security threats.
 
provides only a partial view of what is really going on in your network.
 
introduces risk in not being able to provide detailed information that may be required with mounting compliance and regulatory requirements being placed on IT.
 
Even if a solution can meet your needs currently will it be able to meet your growing needs in the future - when will it finally fail?
NetFlow Auditor License Investment
NetFlow Auditor comes in multiple license tiers for Performance and Professional; The Performance license scales well beyond other products in the NetFlow arena and is designed to provide only real-time functionality with top analysis data in line with the other NetFlow products; the Professional license allows full raw flow capture and forensics with long-term trending. NetFlow Anomaly Detection and Ultra-Long Term Trending and Billing are optional add-on modules.
Download NetFlow Auditor Performance Monitoring Data Sheet