The short version
- When users complain the network is sluggish, the answer is almost always hiding in one of two metrics: which host or application is monopolising…
- A top-talkers view ranks endpoints — or applications, or users — by the volume of traffic they generate over a given window.
- Saturation is the companion metric: it tells you how close a given interface is to its maximum capacity.
01The two numbers that explain almost every "internet feels slow" complaint
When users complain the network is sluggish, the answer is almost always hiding in one of two metrics: which host or application is monopolising the link right now, and how close that link is to its ceiling. Everything else is detail.

02Top Talkers
A top-talkers view ranks endpoints — or applications, or users — by the volume of traffic they generate over a given window. Flow data (NetFlow, sFlow, IPFIX) is the practical source here: your router or firewall exports flow records to a collector such as ntopng or ElastiFlow, and the collector builds the ranked list without touching packet contents. DNS logs and proxy logs can supplement this, attributing raw byte counts to named services rather than bare IP addresses.
The list is rarely surprising once you see it. A backup job hammering cloud storage, a developer pulling large container images, a meeting room endpoint streaming 4K video — these account for a disproportionate share of the link, and they're invisible until you look. Addressing a single top talker (rescheduling the backup, applying QoS to the video endpoint) often recovers more headroom than any hardware upgrade.
03Interface Saturation
Saturation is the companion metric: it tells you how close a given interface is to its maximum capacity. SNMP polling delivers this cheaply — devices report cumulative byte counters, and your monitoring platform (PRTG, LibreNMS, Zabbix) graphs the rate against the interface's known maximum. When that ratio climbs toward 100 %, users feel it as latency and retransmissions, not as a clean "network is down" error.
The critical word is sustained. A one-second burst to 95 % matters less than fifteen minutes sitting at 80 %. Most tools default to five-minute SNMP polling intervals, which smooth out short spikes entirely. If you're chasing intermittent complaints, drop the poll interval or cross-reference with flow data, which captures per-conversation timing at finer granularity.

04Averages Lie
A 40 % average utilisation graph looks comfortable. It can still hide a link that saturates completely for three minutes every hour — exactly when a scheduled task fires, or when the morning standup video calls stack up. The fix is percentile reporting: the 95th-percentile throughput figure discards the top 5 % of measurements and gives you the realistic busy-hour load your link actually sustains. If that number is nudging capacity, you have a real problem regardless of what the average says.
Identify the top talkers, watch the 95th-percentile saturation, and most "slow internet" conversations become short ones.