
This way, it actually covers the most critical threats that network face nowadays, such as advanced persistent threats, inside threats, and even employee abuse, unauthorized access and data leak cases. And, you also have a historic data archive for later investigation whenever deemed necessary. Further analysis of SIEM events can be explored thanks to NetFlow data. Unlike signature-based anti-viruses, facing known threats, this concept of not-preventing but quick-reacting is necessary for rising zero-day attacks. It compliments firewalls, centered on end points of the network, by providing inside view of the network. In general, NetFlow Analyzer software is an essential part of any security infrastructure for detecting anomalies in the network and troubleshooting threat incidents. NetFlow version 9 is the latest version, created to support advanced technologies such as MPLS, IPv6, Multicast, VLANs, etc.

Version 5 is commonly used on most Cisco NetFlow enabled devices. There are numerous NetFlow protocol versions, most important of which are versions 5 and 9. NetFlow Analyzer performs all of these functions. It can then be reviewed in a more user-friendly form. This data is exported to a server, where it is collected, processed, aggregated and archived. NetFlow is a network protocol, developed by Cisco Systems, used for exporting collected IP flow traffic.

Line charts show the usage patterns over time. Pie charts show the distribution of bandwidth across different types of traffic (e.g., HTTP, FTP, VoIP) and across different users. NetFlow Traffic Analyzer converts that data into charts and tables providing network engineers with a easy way to identify and isolate the cause and source of network problems, as well as provide historical performance information to help plan for future growth. By leveraging Cisco's NetFlow protocol to extract data from routers, NetFlow Traffic Analyzer provides an in-depth view into which users and applications are consuming the most bandwidth. Orion NetFlow Traffic Analyzer provides a new level of visibility into network traffic behavior and trends.
