NetFlow (Flow Monitoring)
NetFlow collects metadata about traffic flows for visibility and troubleshooting.
Updated: 2026-03-05
Definition
Flow monitoring (NetFlow/IPFIX) captures metadata about conversations: source/destination, ports, bytes, and timing.
It helps detect unusual traffic patterns and identify top talkers.
Key points
- Traffic visibility beyond packet captures
- Useful for capacity planning and security detection
- Exports flow records to a collector
Common mistakes
- Assuming it captures payload (it’s metadata, not full content).
- Not sizing collectors/storage for high-volume networks.
Related exams
Related terms
Want to practice this in exam-style questions?
Use the mini tests on each exam page, then continue in the app for offline packs and detailed explanations.
Go to exams