How Trisul Works
What is Trisul
Trisul Network Analytics is a software suite that takes network packets or flow data and extracts traffic metrics, flow analysis, alerts, and metadata from them. The applications of Trisul include deep network traffic management, network security monitoring, threat hunting, incident detection, and audit.
Users of Trisul view these analytics reports through a dashboard that opens in any web browser.
Platforms
Linux based Trisul runs on Ubuntu and RHEL/CentOS/OracleLinux based systems.
It has native support for advanced high speed packet capture and load balancing mechanisms like RX_RING, PF_RING, AF_PACKET, and various proprietary hardware acceleration.
Products
Using specialized configuration and extensions we've tailored the Trisul platform into products that fit specific use cases.

The four product modes are:
- Trisul NetFlow Analyzer: traffic analytics from flow records exported by routers and switches.
- Trisul NSM: network security monitoring from raw packets (SPAN or TAP), plus IDS alerts.
- Trisul IPDR DoT Compliance Solution: IPDR logging for ISPs that must meet India DoT rules.
- Trisul ISP Analytics: AS, prefix and peering analytics for carriers and ISPs.
To compare them, see Product Modes.
📝 The Trisul documentation covers the parts common to all four products. Each product's own workflows are in its product guide.