Solutions at a Glance
The table below shows which Modules need to be enabled to turn on NetFlow Optimizer specific solutions.
Network Conversations Monitor (⭐ Primary Module)
The Network Conversations module is one of the main processing engines in NFO. It provides a comprehensive, centralized view of all network activity and is designed to handle all major flow formats, including standard NetFlow, IPFIX, sFlow, and native Cloud Flow Logs (AWS, Azure, GCP, Oracle). This module is the recommended foundation for all new flow data processing and reporting.
| Module Name (nfc_id) | Description |
|---|---|
| Network Conversations Monitor (20062) | This Module reports consolidated network conversations. Optionally it stitches client-server request-response flows, reporting bytes and packets server-to-client and client-to-server in separate fields. It also calculates and reports conversation duration, direction (inbound / outbound), state (Begun, Continues, Ended), action (Accepted / Rejected), etc. ⭐ Primary volume reduction Module for bidirectional flows. This Module will be packaged in Unified Flow Analytics Module Set. |
Network Traffic and Devices Monitor Module Set (⚠️ Partially Deprecated)
The Top Traffic Monitor Module is a primary volume reduction module that consolidates unidirectional flow records into aggregated flow events, significantly reducing data volume for cost reduction in downstream SIEMs. You have the flexibility to report all consolidated flows for analysis or focus only on the Top N most significant conversations based on customizable metrics.
Several Modules in this set will be ⚠️ DEPRECATED or ℹ️ Legacy Module in a future NFO release.
| Module Name (nfc_id) | Description |
|---|---|
| Network Subnets Monitor (20011) | Reports top bandwidth consumers for each monitored subnet. (ℹ️ Legacy Module) |
| TCP Health Monitor (20060) | This Module reports TCP Health by detecting top hosts with the most TCP Resets. (ℹ️ Legacy Module) |
| Top Connections Monitor (20063) | This Module identifies hosts with the most connections. (⚠️ DEPRECATED) |
| Top Pairs Monitor (20064) | This Module reports top Host Pairs network conversations. (⚠️ DEPRECATED) |
| CBQoS Monitor (20065) | This Module reports traffic for all DSCP bits combinations (QoS). (ℹ️ Legacy Module) |
| Traffic by Autonomous Systems (20066) | This Module reports traffic by all Autonomous Systems (AS). (⚠️ DEPRECATED) |
| Top Traffic Monitor (20067) | This Module identifies hosts with the most traffic. ⭐ Primary volume reduction Module for unidirectional flows. This Module will be packaged in Unified Flow Analytics Module Set. |
| Top Packets Monitor (20068) | This Module identifies hosts with the most packets. (⚠️ DEPRECATED) |
Cisco AnyConnect Traffic Monitor
| Module Name (nfc_id) | Description |
|---|---|
| Cisco AnyConnect Top Traffic Monitor (20567) | This Module reports Cisco AnyConnect NVM Flow Logs with logged user information. (ℹ️ Legacy Module) |
Utilities Module Set
This Module Set will be split into two Module Sets in a future NFO release.
| Module Name (nfc_id) | Description |
|---|---|
| Sampling Monitor (20002) | This Module reports NetFlow sampling information. (ℹ️ Legacy Module) |
| SNMP Information Monitor (20003) | This Module reports SNMP information. This Module will be packaged in Infrastructure Telemetry Module Set. |
| SNMP Custom OID Sets Monitor (20103) | This Module enables you to build OID sets for SNMP polling and reporting, using built-in SNMP polling service (supports SNMP v2c and v3). This Module will be packaged in Infrastructure Telemetry Module Set. |
| SNMP Traps Monitor (20700) | This Module enables you to report SNMP traps using built-in SNMP service (supports SNMP v2c and v3). This Module will be packaged in Infrastructure Telemetry Module Set. |
| Auto-discovery Reporter (20701/20702) | This Module reports auto-discovered devices and connections between devices. This Module will be packaged in Infrastructure Telemetry Module Set. |
Services Monitor Module Set
These Modules will be packaged Legacy Module Set.
| Module Name (nfc_id) | Description |
|---|---|
| DNS Service Monitor (20004) | This Module monitors DNS servers and reports DNS server statistics based on DNS traffic. |
| DNS Users Monitor (20005) | This Module monitors DNS users and reports DNS usage statistics based on DNS traffic. |
| Asset Access Monitor (20014) | This Module monitors traffic to selected services and matches communications to a list of authorized peers. |
| Services Performance Monitor (20017) | This Module monitors services performance characteristics. |
Amazon AWS VPC Flow Logs Module Set (⚠️ Deprecated)
This Module Set will be retired in a future NFO release. Its functionality is now fully integrated into the Network Conversations module. Action Required: Please disable this module and migrate your configurations to Network Conversations to eliminate duplicate data reporting to your SIEM or IT Ops system.
| Module Name (nfc_id) | Description |
|---|---|
| AWS Top Traffic Monitor (20267) | This Module reports EC2 instances and hosts with the most traffic. It enriches IP addresses with EC2 names, VPC names, and AWS regions. |
| AWS VPC Flow logs (20201) | This Module reports Amazon VPC Flow Logs ingested from CloudWatch (using Kinesis or CWL API) or S3 translating them one-to-one. |
Microsoft Azure NSG Flow Logs (⚠️ Deprecated)
This Module Set will be retired in a future NFO release. Its functionality is now fully integrated into the Network Conversations module. Action Required: Please disable this module and migrate your configurations to Network Conversations to eliminate duplicate data reporting to your SIEM or IT Ops system.
| Module Name (nfc_id) | Description |
|---|---|
| Azure Top Traffic Monitor (20467) | This Module reports Azure Cloud VM and hosts with the most traffic. It enriches IP addresses with VM names, Virtual Network names, and regions. |
| Azure NSG Flow Logs (20401) | This Module reports Azure NSG Flow Logs ingested from Microsoft Azure Cloud translating them one-to-one. |