Flow records tell you exactly who's hogging your link — and you don't need a packet sniffer or a networking PhD to make sense of them.

The short version

  • NetFlow, and its modern IETF-standard successor IPFIX, works on a simple idea: instead of capturing every packet, your router or firewall summarises each conversation…
  • Most enterprise-grade routers and firewalls can export flow records with a few lines of configuration.
  • Raw flow records are just UDP datagrams landing in a collector.

01What a Flow Record Actually Is

NetFlow, and its modern IETF-standard successor IPFIX, works on a simple idea: instead of capturing every packet, your router or firewall summarises each conversation into a compact record. That record contains source and destination IP addresses, ports, protocol, byte count, packet count, and timing. What it does not contain is any payload — no message bodies, no file contents, no browsing history in any readable form. A flow record tells you that host 192.168.1.42 sent 400 MB to a particular cloud IP over port 443 during a two-hour window. It doesn't tell you what was in those packets, and that's by design. You get full traffic accountability with no privacy-invasive content capture.

sFlow, common on switches from vendors like Arista and Juniper, works slightly differently — it samples packets at a configurable rate rather than tracking every flow — but the output is similar: metadata about conversations, not their contents. All three formats (NetFlow v5, NetFlow v9, IPFIX) are handled by the same generation of collectors, so the choice of which your device exports is usually just a matter of what it supports.

Screenshot or clean diagram of a flow record's fields (src IP, dst IP, ports, bytes, protocol) with payload area struck out
Flow record fields — source IP, destination IP, ports, bytes, protocol — payload area struck out

02Turning on the Tap

Most enterprise-grade routers and firewalls can export flow records with a few lines of configuration. On a Cisco IOS router, you enable flexible NetFlow on a WAN interface, define a flow monitor pointing at your collector's IP and UDP port (2055 is the NetFlow convention; 4739 is the IPFIX default), and the device starts sending records. pfSense and OPNsense support IPFIX export natively through their softflowd package — enable it in the GUI, point it at a collector, and you're done inside ten minutes. Fortinet, Palo Alto, and Ubiquiti gear all have equivalent options, though the menu paths differ; the principle is identical everywhere.

One practical decision: export at the WAN interface (your internet edge) if you want to see external usage; export at core switch uplinks if you need to see internal east-west traffic too. For most small-to-medium offices chasing bandwidth hogs and shadow IT, WAN egress is the right starting point.

03Making Sense of It: Collectors That Do the Work

Raw flow records are just UDP datagrams landing in a collector. The tool that transforms them into something an admin can act on is the collector-plus-analyser, and here the open-source options are genuinely good.

ntopng (the web front-end for ntop's stack) accepts NetFlow and IPFIX, resolves IPs to hostnames and country, classifies traffic by application using deep flow inspection of metadata (not payload), and surfaces a live ranked view of top talkers within minutes of setup. The Community edition is free and handles modest traffic volumes comfortably. ElastiFlow takes a different approach: it parses and normalises flow records and ships them into an Elasticsearch or OpenSearch backend, where a Kibana or OpenSearch Dashboards deployment gives you flexible, drillable visualisations. It scales well into multi-site environments and is particularly strong for historical trending and capacity planning.

Both tools answer the questions that matter most: Which hosts are generating the most traffic? Which external destinations are they talking to? What mix of applications — video streaming, backup traffic, SaaS sync, Microsoft 365, encrypted peer-to-peer — is on the link right now? Because they resolve destination IPs to hostnames, they can identify many HTTPS destinations even without decrypting anything.

For environments already running PRTG or LibreNMS, both products include flow collection and basic top-talker reporting, so you may not need a dedicated tool at all — check what's already licensed before adding another stack.

ntopng or ElastiFlow dashboard screenshot showing top-talkers ranked table
ntopng or ElastiFlow top-talkers dashboard ranking hosts by traffic volume

04From Numbers to Action

Once you have ranked top-talker data, the path to action is short. An unexpected host sending sustained gigabytes to an unfamiliar IP is a security question. A department's workstations hammering a cloud backup service every Monday morning is a scheduling and QoS question. A single user accounting for a disproportionate share of egress during business hours is a conversation — not an accusation, but one that benefits from data.

NetFlow doesn't replace a full security stack, and it won't tell you what's inside a TLS session. But for understanding who and what is consuming your link, it is the most efficient technique available: low overhead, no endpoint agents, no content capture, and answers in a dashboard rather than a packet file.

05Tools & references mentioned