
Instead, the Flow Collector just receives the flow records and another application does this analysis. Note: In some instances, the Flow Collector does not do the actual analysis of the flow records. On the other hand, the Flow Collector receives flow records from the exporter, processes them and can analyze this information to be presented to users in sensible form. This exporter is usually configured on a device such as a router or a switch and in some cases, there may be multiple exporters for different flows. The Flow Exporter captures flow information to be sent to a collector. When NetFlow is implemented on a network, there are usually two major components: Flow Exporter and Flow Collector. nProbe runs on Linux and Windows and ntopng is available for Windows, Linux, macOS, RaspbianOS, and FreeBSD.

The type of information collected from IP traffic by NetFlow to determine a flow include:īy collecting this information and analyzing it, a lot of insight can be gained about the network and used for several purposes including bandwidth monitoring, network performance troubleshooting and anomaly detection.

NetFlow is a protocol developed by Cisco used to collect information about traffic flowing through devices on a network.
