Trisul NetFlow Analyzer Guide
Welcome to the Trisul NetFlow Analyzer Guide.
Trisul NetFlow Analyzer is designed for monitoring and analyzing network traffic using flow data collected from routers, switches, and other network devices. It supports NetFlow v5/v9, IPFIX, sFlow, and NetStream.
With NetFlow Analyzer, you can use flow data to:
- See how much traffic is flowing through your network
- Identify the hosts, applications, and interfaces generating traffic
- Investigate traffic patterns over time
- Monitor network capacity and utilization
- Track unusual or suspicious traffic
- Generate traffic and usage reports
- Investigate historical traffic without having to capture packets again
Before you begin
If you have not installed Trisul yet, start with the installation guide.
During installation, select NetFlow Analyzer as the Product Mode. This configures Trisul for collecting and analyzing flow data from your network devices.
Install Trisul and select NetFlow Analyzer mode
Once Trisul is installed and you have logged in to the Web UI, return to this guide to learn how to use the NetFlow Analyzer interface.
The screens and menus described in this guide are available when Trisul is configured in NetFlow Analyzer mode. If you selected a different Product Mode during installation, your Web UI may have a different menu structure.
What you will find in this guide
The NetFlow Analyzer Web UI is organized into seven main menu categories. Each category helps you perform a different type of network monitoring or analysis.
🗃️ Dashboards
Use dashboards for a quick view of what is happening in your network. You can monitor current traffic, active hosts, applications, alerts, security information, sessions, and other frequently used network metrics.
🗃️ Retro
Use Retro when you want to look back at network activity that has already happened. It lets you inspect historical counters and analyze traffic for a specific period in the past.
🗃️ Tools
Use the Tools section when you need to investigate traffic in more detail. It includes flow exploration, historical trends, IP flow exports, usage charts, flow trackers, taggers, and edge connection graphs.
🗃️ Netflow
Use the Netflow section to understand where your flow data is coming from and how traffic is distributed across your network devices and interfaces. You can view NetFlow sources, exporters, routers, interfaces, and interface-level traffic details.
🗃️ Alerts
Use Alerts to identify traffic conditions that require attention. You can configure Threshold Crossing Alerts (TCAs), flow tracking alerts, blacklist matching, dynamic threshold bands, and view alert activity.
🗃️ Reports
Use Reports when you need to turn network traffic data into reports that can be reviewed or shared. This section includes standard reports, scheduled recurring reports, and email delivery settings.
🗃️ Customize
Use Customize to adjust how the NetFlow Analyzer Web UI behaves and looks. You can personalize dashboard layouts, real-time parameters, and HTTP/HTTPS traffic classification rules.