NetFlow tells you who is talking to whom and how much data they exchange. SNMP tells you interface utilization. NetFlow tells you what is consuming that bandwidth.
A flow is defined by:
- Source and destination IP addresses
- Source and destination ports
- Protocol
- Input interface
Routers track flows as packets pass through. When a flow ends, the router exports a summary record to your collector.
NetFlow shows you:
- Top talkers consuming bandwidth
- Application usage patterns
- Traffic distribution between locations
- Potential security incidents