Fundamentals
What network-usage monitoring is, what it can and can't tell you, and the four data sources it draws on — logs, flows, packets and DNS.
- 01
What Network-Usage Monitoring Actually Tells You
The mental model: usage monitoring answers who/what/how-much on your link — not whether a remote service is up. What it reveals (bandwidth by host/app, sites & cloud apps, session patterns) and what it deliberately does NOT (message content). Set expectations honestly.
- 02
Logs vs Flows vs Packets vs DNS
The four data sources of usage visibility, compared: proxy/access LOGS (per-user web history), FLOWS (NetFlow/sFlow/IPFIX — who talked to whom, how much, no payload), PACKETS (full detail, heavy, privacy-sensitive), and DNS (every lookup, cheap, content-free). When to reach for each; the privacy and volume trade-offs.
- 03
Monitoring Usage Without Reading Content
The privacy-respecting core: you can see volumes, destinations and patterns without inspecting message bodies. Metadata vs content; why flow/DNS beats packet capture for routine oversight; being transparent with staff; where the legal/ethical lines sit. Echoes the old suite's 'without reading message content' promise, modernised.
- 04
Agentless or Agents? How Monitors Collect Data
Agentless (SNMP, flows, logs, DNS — nothing installed on endpoints) vs agent-based (something running on each host). Coverage, accuracy, deployment cost and privacy implications of each. Internet Access Monitor was agentless by design (it read existing proxy logs); many modern choices still are.