Trisul NetFlow Analyzer Guide
Welcome to the Trisul NetFlow Analyzer Guide.
Trisul NetFlow Analyzer is designed for monitoring and analyzing network traffic using flow data collected from routers, switches, and other network devices. It supports NetFlow v5/v9, IPFIX, sFlow, and NetStream.
With NetFlow Analyzer, you can use flow data to:
- See how much traffic is flowing through your network
- Identify the hosts, applications, and interfaces generating traffic
- Investigate traffic patterns over time
- Monitor network capacity and utilization
- Track unusual or suspicious traffic
- Generate traffic and usage reports
- Investigate historical traffic without having to capture packets again
Before you begin
- Install Trisul. Follow the Quickstart.
- Configure your routers and switches to export flow records to Trisul. See Configure NetFlow.
- Log in to the Web UI and select NetFlow Analyzer as the product mode. You choose the mode on first login, not during installation. See Selecting the Product Mode.
- Confirm that flow data is arriving. Go to NetFlow → NetFlow Sources and check that your flow exporters are sending data. See NetFlow Sources. If no data arrives, see the NetFlow troubleshooting guide.
When data is arriving, use the rest of this guide to learn the NetFlow Analyzer menus.
The screens and menus described in this guide are available when Trisul is configured in NetFlow Analyzer mode. If you selected a different Product Mode during installation, your Web UI may have a different menu structure.
What you will find in this guide
The NetFlow Analyzer Web UI is organized into seven main menu categories. Each category helps you perform a different type of network monitoring or analysis.
Start with Dashboards for a live view of your network, then check Alerts to see what has already been flagged. Use Retro once you need to look further back in time. The other menus below are for deeper investigation once you know what you are looking for.
🗃️ Dashboards
Use dashboards for a quick view of what is happening in your network. You can monitor current traffic, active hosts, applications, alerts, security information, sessions, and other frequently used network metrics.
🗃️ Retro
Use Retro when you want to look back at network activity that has already happened. It lets you inspect historical counters and analyze traffic for a specific period in the past.
🗃️ Tools
Use the Tools section when you need to investigate traffic in more detail. It includes flow exploration, historical trends, IP flow exports, usage charts, flow trackers, taggers, and edge connection graphs.
🗃️ NetFlow
Use the Netflow section to understand where your flow data is coming from and how traffic is distributed across your network devices and interfaces. You can view NetFlow sources, exporters, routers, interfaces, and interface-level traffic details.
🗃️ Alerts
Use Alerts to identify traffic conditions that require attention. You can configure Threshold Crossing Alerts (TCAs), flow tracking alerts, blacklist matching, dynamic threshold bands, and view alert activity.
🗃️ Reports
Use Reports when you need to turn network traffic data into reports that can be reviewed or shared. This section includes standard reports, scheduled recurring reports, and email delivery settings.
🗃️ Customize
Use Customize to adjust the NetFlow Analyzer Web UI. You can manage dashboards, modules, dashboard packages, Network FAQ questions and the navigation menu.