Trisul Terminology
Trisul Network Analytics uses a set of terms to describe how traffic is captured, analyzed, stored, and investigated.
Detailed individual counter groups, trackers, and alert types are documented in the dedicated pages of respective topics.
This page focuses on the shared terminology used across them.
The Glossary defines networking, security, and ISP terms. This page covers the terms Trisul uses.
How to Read This Page
Trisul terminology is grouped by conceptual layers, starting from how the system runs, moving through traffic and analytics, and ending with how you interact with the data.
You do not need to memorize these terms. The goal is to make them familiar when you encounter them elsewhere in the UI or documentation.
1. Architecture & Runtime Terminology
These terms describe how Trisul is set up and how its parts work together.
Node
A node is any machine where a Trisul component is installed and running.
A node can run the Probe component, the Hub component, or both, depending on how Trisul is deployed. Probe nodes primarily analyze traffic, while Hub nodes primarily store and serve the analyzed data.
You will encounter this term when installing Trisul or working with deployments that use multiple machines.
Probe
A Probe is a Trisul node that analyzes network traffic.
It receives packets or flow records, processes them, and produces metrics, flows, and alerts. When you view live traffic information or real-time alerts in WebTrisul, the traffic was first processed by a Probe.
Hub
A Hub is a Trisul node that stores and provides access to data generated by Probes.
Probes send their analyzed results to the Hub. The Hub stores this data and provides it when you open dashboards, charts, or searches.
In simple terms:
- Probe analyzes the traffic.
- Hub stores the results and serves them when you need to view or search them.
WebTrisul
WebTrisul is the web-based interface you access in your browser.
It is where you log in to Trisul, view dashboards, explore traffic, investigate alerts, search flows, and manage users.
If you are interacting with Trisul through a web browser, you are using WebTrisul.
Domain
A domain is the top-level administrative boundary in a Trisul deployment.
It groups the Trisul components that belong to the same deployment and establishes the trust relationship between them.
For example, a deployment may contain several Probes and Hubs that communicate with each other within the same domain.
In most deployments, the domain is created during installation and does not require regular user interaction. You are more likely to encounter the term when working with certificates, distributed deployments, or advanced administration.
See also: Domains.
Context
A context is a separate monitoring workspace inside Trisul.
When you select a context in the UI, you are choosing which traffic data, dashboards, alerts, and configuration you are working with. Each context keeps its data and configuration separate from other contexts.
Contexts are useful when you want to monitor different networks or environments separately.
For example, you could have:
- one context for a production network
- another context for a test network
- separate contexts for different customers
Each context can be started, stopped, reset, or deleted independently.
See also: Working With Contexts.
Think of a Context as an office and a Profile as the office's setup blueprint.
A Context is the actual office you are working in. It has its own data, dashboards, alerts, and configuration. Two offices can operate independently even though they belong to the same organization.
A Profile is the blueprint for setting up an office. It defines what equipment and arrangements the office should have, so you don't have to configure every office from scratch.
For example:
Imagine you operate two offices, one for Production and one for Testing.
You create a Production Context and a Test Context. Each context has its own traffic data and can be managed independently.
Both offices need the same setup: the same monitoring equipment, measurements, flow tracking, and alerts. Instead of configuring both contexts separately, you use the same Profile for both.
If you create another context with the same requirements, you can assign the same profile to it.
Profile
A profile is the configuration used by a context to decide how traffic is analyzed.
It controls capture settings such as interfaces and filters, the counters that are measured, flow tracking, alerts, resources, and other analytics options.
You assign a profile to a context from the CLI. That profile defines:
- which counters are available
- which alerts are enabled
- how flows are tracked
If you want another context to use the same setup, you can reuse or duplicate the profile instead of configuring everything again.
In simple terms, a profile lets you reuse the same monitoring setup across contexts.
GUID
A GUID is a globally unique identifier used by Trisul to uniquely identify internal objects.
GUIDs are used to distinguish things like counter groups, trackers, alerts, or configuration objects from one another, even if they have the same name.
Trisul generates GUIDs automatically. You will mainly encounter them when working with configuration files, APIs, exports, or troubleshooting.
See also: GUID reference.
Machine ID
A Machine ID is a unique identifier assigned to a specific system where Trisul is installed.
It helps Trisul identify the machine for purposes such as licensing, deployment identity, and internal coordination.
In simple terms, the Machine ID answers:
“Which machine is this Trisul installation running on?”
The Machine ID is tied to the system and is not intended to be manually changed or reused on another machine.
Flush Time
Flush Time is the time Trisul takes to collect the latest streaming data and send a snapshot of that data to Trisul-Hub.
It is a measure of how quickly the Probe can prepare and hand over its latest results to the Hub.
You will mainly encounter Flush Time when looking at Trisul system performance.
IOP (Input/Output Operation)
IOP (Input/Output Operation) is a read or write operation performed on a storage device.
For example, reading data from a disk and writing data to a disk are both input/output operations.
IOP is useful when looking at storage performance because a system that performs many read/write operations can place a higher workload on its storage devices.
2. Deployment & Mode-Specific Terminology
These terms describe how Trisul is deployed and what type of traffic data it processes.
Packet Capture Mode
Packet mode analyzes traffic using captured network packets.
Packet capture mode is a processing mode, not a product mode. See Processing Mode.
In this mode, Trisul works directly with packet data, allowing inspection at the protocol and payload level.
Packet mode provides detailed visibility into the traffic because Trisul can work with the actual packets rather than only with summaries of the traffic.
Flow-Based Mode
Flow mode is a processing mode where Trisul analyzes traffic using flow records exported by network devices instead of captured packets.
Flow records contain summaries of network conversations rather than the original packets.
The information available in Trisul therefore depends on what fields are included in the received flow records.
Home Network
In Trisul, home network means the network that you have configured as your own or monitored network.
The term home network does not mean that Trisul is only used for a home or residential network. It can refer to an organization's network, a data center network, a campus network, or any other network that you are monitoring.
For example, if Trisul is monitoring a company's network, the company's computers, servers, phones, and other network devices belong to the home network.
This definition is important because Trisul uses the home network to determine whether traffic is inbound, outbound, or transit.
By default, Trisul treats the RFC 1918 private ranges 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 as the home network.
See also: Home Network Concepts. To add or edit home networks, see Home Networks.
Internal Hosts
Internal Hosts are hosts that belong to your home network.
For example, they can include:
- Employee computers
- Laptops
- Mobile phones
- Servers
- Printers
- Network devices
- Other devices connected to your network
When a Trisul dashboard shows Internal Hosts, it is referring to devices that belong to the network you are monitoring.
Inbound / Outbound / Transit Traffic
Traffic direction is determined relative to the home network:
- Inbound traffic enters the home network.
- Outbound traffic leaves the home network.
- Transit traffic passes through the network without originating or terminating inside it.
- Internal traffic stays inside the home network. Both the source and the destination are home-network addresses.
For example, if a computer inside your network downloads data from an Internet server, the traffic entering your network is inbound.
If a computer inside your network sends data to an Internet server, the traffic leaving your network is outbound.
This classification is used throughout Trisul to group and report traffic by direction.
The UI uses both sets of direction labels: Inbound or Incoming, and Outbound or Outgoing.
Upload
Upload refers to data being transferred out of your network to an external destination.
For example, when a computer in your network sends a file to an Internet service, that data transfer is an upload.
Download
Download refers to data being transferred into your network from an external destination.
For example, when a computer in your network receives a file from an Internet service, that data transfer is a download.
External Hosts
External hosts are systems outside your home network.
These may include:
- Websites
- Internet servers
- Cloud services
- Remote servers
- Other systems communicating with your network
For example, when a computer on your network accesses a website, your computer is an internal host and the web server it communicates with is an external host.
3. Traffic & Flow Model Terminology
These terms describe what Trisul observes on the network.
Packet
A packet is a single unit of network data captured from the wire.
Packet-level visibility is mainly used in packet capture mode and allows detailed inspection and forensic analysis.
PCAP (Packet Capture)
PCAP (Packet Capture) refers to captured raw network packets that can be stored for later analysis.
A PCAP contains the actual packets observed on the network rather than only a summary of the communication.
PCAP data can therefore be used when you need to examine traffic at the packet level.
Dropped Packet
A Dropped Packet is a packet that was not successfully processed by the packet capture or processing pipeline.
Dropped packets are important because they can indicate that Trisul was unable to keep up with the traffic being received.
The System Performance dashboard can help you see whether packets are being dropped.
Flow
A flow represents a network conversation between endpoints.
Instead of storing every packet as a separate item for flow analysis, Trisul summarizes the communication into a flow using information such as:
- source and destination addresses
- ports
- protocol
- amount of data
- number of packets
- duration
For example, when a computer accesses a website, the communication between the computer and the web server can be represented as a flow.
Flows make it practical to analyze large volumes of network traffic without examining every packet individually.
IP Flow
An IP Flow is a flow identified at the IP layer between communicating endpoints.
It represents communication between IP addresses and can be used to understand which systems are exchanging traffic and how much traffic they exchange.
Long-Lived Flow
A Long-Lived Flow is a network flow that remains active for a long period of time.
A long-lived flow does not necessarily transfer a large amount of data. A connection can stay open for a long time while transferring relatively little data.
This is useful when looking for connections that remain active for an unusually long period.
TCP Payload
TCP Payload is the actual application data carried inside a TCP connection.
It does not include the additional TCP information used to transport that data.
For example, when a TCP connection transfers a file, the file data is part of the TCP payload, while TCP headers used to manage the connection are not.
TCP payload is useful when you want to measure the amount of actual data transferred rather than the total traffic generated by the TCP connection.
Flow Record
A flow record is the stored form of a flow.
It contains information such as timestamps, counters, and attributes that describe the network conversation.
Flow records are what you search, filter, and analyze in flow investigation tools.
Application
An application identifies the type of network service associated with traffic.
For example:
- HTTP and HTTPS are commonly associated with web traffic.
- SSH is commonly associated with remote access.
- DNS is commonly associated with domain-name lookups.
Trisul identifies applications in network traffic and groups traffic by application. This allows you to see how much traffic each application generates and how frequently it is used.
Bi-directional Flow
A bi-directional flow includes traffic in both directions between two endpoints and represents a complete conversation.
This is how Trisul typically shows flows when it can see both sides of the exchange. Bytes, packets, and duration reflect the complete back-and-forth, making it easier to understand who talked to whom and how much data was exchanged overall.
For most users, this is the default and most intuitive view of network traffic.
Uni-directional Flow
A uni-directional flow represents traffic observed in only one direction.
This occurs when the traffic source or capture point reports each direction separately, or when only one direction of the traffic is visible at the observation point.
In such cases, Trisul records exactly what it sees.
As a result, a single network conversation may appear as two separate flows, one for each direction. This is expected behavior and reflects how the traffic was observed, not a duplication or error in analysis.
Observation Point
An observation point is where Trisul sees the network traffic.
It could be:
- a physical network interface
- a router
- a firewall
- a traffic tap
- a SPAN port
- a flow exporter
Knowing the observation point helps you understand where the traffic data was collected in the network.
4. Analytics & Counters Terminology
These terms describe how Trisul measures and summarizes traffic.
Counter Group
A counter group defines a category of things that Trisul measures.
Each counter group groups together similar items, such as hosts, applications, interfaces, or autonomous systems.
Counter groups exist so Trisul knows what type of entities it is analyzing.
Each counter group has its own set of measurements and its own dedicated documentation page.
Key
A key represents a single thing being measured within a counter group.
You can think of a key as the item Trisul is tracking inside a counter group.
For example:
- an IP address is a key in the Hosts counter group
- an application name is a key in the Apps counter group
When you see toppers, charts, or tables, you are often seeing keys ranked by their metrics.
-
Counter Group is a group that tracks the same type of information. Each value tracked within the group is a key.
For example:
-
Apps is a counter group that tracks application names.
https,http, andimapare keys within the Apps counter group. -
Hosts is a counter group that tracks individual hosts. For example,
192.168.1.10and10.0.0.5are keys within the Hosts counter group. -
Country is a counter group that tracks individual countries. For example,
United States,India, andChinaare keys within the Country counter group. -
ASN is a counter group that tracks individual AS numbers. For example,
15169and3356are keys within the ASN counter group.
-
Meter
A meter defines what Trisul measures for each key.
Examples include:
- bytes
- packets
- flows
- errors
A counter group can have multiple meters, with each meter measuring a different aspect of traffic.
Metric
A metric is the numeric value produced by a meter over a period of time.
Metrics are the actual numbers you see on charts, use in alerts, and export in reports.
Example:
Meter: Total Bytes
Metric: 1.2 GB at 10:05
Packets Wire
Packets Wire is the number of packets seen per minute by the packet capture mechanism.
It helps you understand how much packet traffic the Probe is receiving from the network.
Bandwidth
Bandwidth is the rate at which data is being transferred.
It is displayed as a rate such as Kbps or Mbps.
For example, if a dashboard shows 100 Mbps, it means the network is currently transferring data at a rate of approximately 100 megabits per second.
In
In is the amount of data received by the network during the selected time period.
In Trisul dashboards, it normally refers to traffic entering the monitored home network.
Out
Out is the amount of data sent from the network during the selected time period.
In Trisul dashboards, it normally refers to traffic leaving the monitored home network.
Active Flows
Active Flows is the number of network flows that are currently active.
It gives you an idea of how many network conversations are taking place at the same time.
For example, a high number of active flows can mean that many devices or applications are communicating simultaneously.
Active Internal IPs
Active Internal IPs is the number of internal IP addresses that are currently active.
It tells you approximately how many devices or systems inside your monitored network are participating in network activity during the selected period.
Top Hosts
Top Hosts are the hosts associated with the highest traffic rates.
A Top Hosts view helps you quickly identify which devices or systems are generating the most network traffic.
Top Apps
Top Apps are the applications associated with the highest traffic rates.
A Top Apps view helps you quickly identify which applications are responsible for the most network traffic.
Data Volume
Data Volume is the total amount of data transferred during the selected time period.
It is displayed as a data size such as MB or GB.
For example, if a dashboard shows 5 GB of Data Volume, it means 5 GB of data was transferred during the selected period.
Topper / Top-N
A topper shows you the highest-ranking keys for a selected metric and time range.
Instead of looking through every host, application, or other key, a topper shows the items that rank highest.
For example:
- Which hosts used the most bandwidth?
- Which applications generated the most traffic?
- Which ASNs carried the most traffic?
Toppers are useful when you want to quickly find the largest contributors to network activity.
Cardinality
Cardinality tells you how many different keys were active in a counter group during a given time period.
For example:
- How many different hosts communicated on the network?
- How many unique applications were seen?
- How many ASNs contributed traffic?
Cardinality is about the number of different participants, not the amount of traffic they generated.
For example, a network could have:
- high traffic generated by a small number of hosts, or
- moderate traffic generated by a very large number of hosts.
Cardinality helps you distinguish between these situations.
Hi Water
Hi Water is the upper threshold used to indicate that a monitored value has reached a specified high level.
When a value reaches or exceeds the Hi Water level, the feature using the threshold can take the configured action or indicate that the high threshold has been crossed.
The meaning of the Hi Water value depends on what is being monitored. It can be used with metrics such as traffic volume, bandwidth, number of active keys, and other measurements.
Low Water
Low Water is the lower threshold used to indicate that a monitored value has fallen to a specified low level.
When a value reaches or falls below the Low Water level, the feature using the threshold can take the configured action or indicate that the low threshold has been crossed.
The meaning of the Low Water value depends on what is being monitored. It can be used with metrics such as traffic volume, bandwidth, number of active keys, and other measurements.
CPU Usage
CPU Usage shows how much of the system's processing capacity is being used by the operating system and Trisul Probe.
A high CPU usage value means the system is using a large part of its available processing capacity.
CPU Usage is a system performance measurement, not a measure of network traffic.
Memory Usage
Memory Usage shows how much system memory is being used by the operating system and Trisul Probe.
It helps you understand how much of the machine's available memory is currently being used.
Memory Usage is a system performance measurement, not a measure of network traffic.
PCAP Disk Bandwidth
PCAP Disk Bandwidth is the rate at which raw packet capture data is written to disk.
It helps you understand how much disk activity is being generated by packet capture.
Front End
Front End refers to the streaming pipeline or engine through which network packets are received and processed.
5. Time, Storage & Retention Terminology
These terms explain how data is stored and managed over time.