NetFlow is a technology, introduced by Cisco, that records metadata about the traffic passing through a network device: who talked to whom, over what protocol, and how much data moved, without capturing the contents of the packets.
The device groups packets into flows, a flow being all the packets that share the same source and destination address, ports and protocol, and it exports a small summary record for each flow to a collector.
That collector stores the records and an analysis application turns them into answers about bandwidth, traffic mix and security. Because NetFlow reports metadata rather than payloads, it is a lightweight way to see the shape of network traffic.
- NetFlow records metadata about traffic flows, not the packet contents
- A flow is packets that share source and destination IP, ports and protocol
- The device exports a summary record per flow to a collector
- It answers who talked to whom, over what, and how much
- IPFIX is the IETF standard built on NetFlow version 9
On this page
What it isWhat NetFlow is
NetFlow answers a question packet counters cannot: not how much traffic, but what kind and between whom.
It records traffic metadata. NetFlow is a flow monitoring technology used to collect and export metadata about IP traffic flows, not the packet payloads, from network devices. It was introduced on Cisco routers to collect IP network traffic as it enters or exits an interface.
It sees conversations, not contents. A NetFlow record says that one address sent a certain number of bytes and packets to another address, over a given protocol and port, during a window of time. It does not record what was in those packets. That is the difference between knowing two people spoke for an hour and knowing what they said.
It is built into the network device. The router or switch itself watches the traffic crossing its interfaces and produces the flow records. There is no separate tap or probe in the basic case; the forwarding device is also the observer.
What a flow isWhat a flow is
The whole model rests on the definition of a flow, and it is precise.
A flow is packets that belong together. A flow is the set of packets that share the same key fields: source IP address, destination IP address, source port, destination port, and protocol. Every packet matching that key during a time window is counted into one flow record.
Cisco's classic key added more. The original Cisco NetFlow keyed a flow on seven fields, adding the type of service byte and the input interface to the five above. The exact key can vary by version and configuration, but the idea is constant: packets with the same key are one flow.
A flow is one direction. A flow is unidirectional, so a conversation between two hosts is usually two flows, one each way. Adding them together is how an analyzer reconstructs a two-way exchange.
ArchitectureThe NetFlow architecture
Three roles turn raw traffic into usable information, and they are worth naming.
The exporter makes the records. The flow exporter is the device that aggregates packets into flows and exports flow records toward one or more collectors. This is the router or switch doing the watching.
The collector receives them. The flow collector is responsible for the reception, storage and pre-processing of the flow data sent by the exporters. It is where the records accumulate, usually delivered over UDP.
The analyzer makes sense of them. An analysis application reads the collected flow data, for intrusion detection, traffic profiling, or reporting. This is the layer that turns thousands of flow records into a dashboard a person can act on. It is a natural companion to broader network management software.
UsesWhat NetFlow is used for
The reason to run NetFlow is that flow metadata answers a lot of questions cheaply.
Traffic analysis. Flow records reveal the top talkers, the bandwidth-heavy hosts, and the application mix on a link, which is the foundation of any real bandwidth management. You cannot manage what you cannot see, and NetFlow is how many networks see it.
Security monitoring. Because it captures who is talking to whom, NetFlow surfaces patterns that signal trouble: DDoS floods, port scanning, data exfiltration, and unusual internal traffic. It is a metadata trail that exists whether or not full packet capture is running.
Capacity planning and billing. Long-term flow data shows how usage grows and where, which informs when a link needs upgrading. The same records can attribute usage for internal chargeback or provider billing.
Versions and IPFIXVersions and IPFIX
NetFlow has evolved, and knowing the versions saves confusion.
Version 5 is the classic fixed format. NetFlow v5 exports a fixed set of fields per flow and is still widely seen on older gear. It is simple but cannot be extended.
Version 9 is template based. NetFlow v9 introduced templates, letting the exporter describe which fields it is sending, so new field types can be added without changing the protocol. It is the flexible successor to v5.
IPFIX is the open standard. IPFIX, sometimes called NetFlow v10 informally although it is a separate IETF standard, is based on NetFlow v9, is standardized by the IETF in RFC 7011, and standardizes flow export across vendors. Where NetFlow is Cisco's technology, IPFIX is the vendor-neutral version of the same idea.
NetFlow vs sFlowNetFlow and sFlow
The other name that comes up next to NetFlow is sFlow, and the two are easy to blur.
NetFlow accounts for every flow. In its unsampled form, NetFlow keeps state for each flow and exports a record that reflects all the traffic in that flow. The device is doing per-flow accounting, so the byte and packet counts are complete rather than estimated.
sFlow samples packets instead. sFlow takes a statistical sample, exporting details of one packet in every so many, and lets the collector infer the totals. It is lighter on the device at very high speeds, at the cost of exact counts, and it is built into a lot of switch hardware for that reason.
Both feed the same kind of monitoring. Whichever the device speaks, the export goes to a collector and an analysis tool reads it, so the traffic-monitoring workflow looks similar. The practical choice is usually decided by what the network hardware supports, and many collectors accept NetFlow, IPFIX and sFlow together so an estate can mix them.
PitfallsWhere people go wrong
Expecting NetFlow to show packet contents. It does not. NetFlow is metadata: addresses, ports, counts and times. To see the actual bytes of a conversation you need full packet capture, which is far heavier.
Confusing the exporter and the collector. The device generates flow records; a separate system stores and analyzes them. A NetFlow deployment that has exporters configured but no working collector produces records that go nowhere.
Assuming every device speaks the same version. A collector has to understand the version each exporter sends. Mixing v5, v9 and IPFIX across an estate without a collector that handles all of them leaves gaps.
Sampling without knowing it. On high-speed interfaces, devices often export only a sample of flows to save resources. Sampled data is fine for trends but will undercount, and treating sampled totals as exact is a common mistake.
Ignoring that flows are one-way. A single conversation appears as two flows. Reporting one direction as the whole exchange halves the real figure.
ComparisonNetFlow, packet capture and SNMP compared
| Criterion | NetFlow | Full packet capture | SNMP counters |
|---|---|---|---|
| What it shows | Who, what, how much (metadata) | Full packet contents | Interface totals only |
| Detail | Per flow | Per packet | Per interface |
| Overhead | Low | High | Very low |
| Answers who talks to whom | Yes | Yes | No |
| Sees payload | No | Yes | No |
| Typical use | Traffic and security analysis | Deep forensic inspection | Basic up/down and volume |
NetFlow sits in the useful middle: far more insight than interface counters, at a fraction of the cost of capturing every packet.
FAQFrequently asked questions
What is NetFlow?
A technology introduced by Cisco that records metadata about the traffic flows passing through a network device, who talked to whom, over what protocol, and how much data moved, and exports a summary record for each flow to a collector for analysis. It does not capture packet contents.
What is a flow in NetFlow?
The set of packets that share the same key fields, at minimum source and destination IP address, source and destination port, and protocol. Every packet matching that key during a time window is counted into one flow record.
Does NetFlow capture packet contents?
No. NetFlow records metadata, addresses, ports, byte and packet counts, and times, not the payloads. Seeing the actual contents of traffic requires full packet capture, which is much heavier.
What is a flow exporter?
The network device, usually a router or switch, that aggregates the packets crossing its interfaces into flows and exports the flow records toward one or more collectors.
What is a flow collector?
The system that receives, stores and pre-processes the flow records sent by the exporters, so an analysis application can query them. Records are typically delivered over UDP.
What is the difference between NetFlow and IPFIX?
NetFlow is Cisco's technology; IPFIX is the IETF standard based on NetFlow version 9, giving a vendor-neutral flow export format. They are the same idea, one proprietary in origin and one standardized.
What are NetFlow v5 and v9?
Version 5 exports a fixed set of fields per flow and cannot be extended. Version 9 is template based, letting the exporter describe which fields it sends, so new field types can be added without changing the protocol.
What is NetFlow used for?
Traffic analysis (top talkers, bandwidth use, application mix), security monitoring (spotting DDoS, scanning and exfiltration), and capacity planning and billing based on long-term usage.
What is the difference between NetFlow and SNMP?
SNMP counters give totals per interface, how much traffic crossed a port. NetFlow gives per-flow detail, who talked to whom and over what. SNMP answers how much; NetFlow answers what and between whom.
What is sampled NetFlow?
On high-speed links, a device may export only a sample of flows to save resources rather than every one. Sampled data is good for trends but undercounts, so it should not be read as exact totals.
Is NetFlow the same as sFlow?
No, though they overlap. sFlow is a separate, sampling-based technology from a different origin. Both export traffic information to a collector, but the flow model and the sampling approach differ.
Does NetFlow slow down the network?
Generating flow records adds some load to the device, which is why high-speed interfaces often sample rather than record every flow. Done appropriately, the overhead is low, far lower than capturing full packets.
Keep readingRelated concepts
Read next · Tools Network Management Software, and the Three Questions It Has to Answer The tooling a flow analyzer usually sits alongside. Open this next11 min- Infrastructure · 11 min Quality of Service, and the Condition It Needs to Do Anything What you prioritize once NetFlow shows the application mix.
- Network operations · 10 min Bandwidth Management, the Four Levers and When to Pull Each The measurement half of managing a link, which NetFlow provides.
- Network operations · 9 min Syslog, the Standard Way Devices Send Their Logs Traffic records to a collector, next to logs to a syslog server.