#ipfix
With the team @free1337.bsky.social, we have developed a Netflow/IPFIX collector and visualizer. It is available at github.com/akvorado/akv.... It relies on several opensource components: GoFlow2, Kafka, ClickHouse, Vue, Tailwind, and more!
GitHub - akvorado/akvorado: Flow collector, enricher and visualizer
Flow collector, enricher and visualizer. Contribute to akvorado/akvorado development by creating an account on GitHub.
github.com
November 17, 2024 at 7:35 AM
Just deployed Akvorado 🚀—a free, open-source NetFlow/IPFIX analyzer—to monitor my ISP network in real time.

✅ ASN + country lookup
✅ Per-router bandwidth
✅ Top apps, protocols, talkers
✅ Self-hosted, zero cost

#Networking #OpenSource #Akvorado #MikroTik #NetFlow
December 29, 2025 at 10:53 AM
Publishing my latest technical blog: SRv6 Observability. This post explores SRv6 observability, featuring a practical example based on my recent contributions to GOFLOW2, an outstanding tool developed by @lsp.bsky.social
SRv6 Observability
How can we monitor SRv6 data plane, collect statistics on the SRv6 SRH and tunnels with IPFIX option 315 / IMON?
community.juniper.net
November 19, 2024 at 9:11 AM
Release of Akvorado version 2.0, an open-source Tool to collect network flows with IPFIX and sFlow - Project by Vincent Bernat @vincent.bernat.ch #Network #Monitoring vincent.bernat.ch/en/blog/2025...
Akvorado release 2.0
Akvorado 2.0 is out! It introduces a major architectural change with a new outlet service, as well as smaller changes detailed in this post.
vincent.bernat.ch
September 24, 2025 at 7:10 PM
Just published Akvorado 2.4.1, your friendly IPFIX/NetFlow/sFlow collector: github.com/akvorado/akv....
Release v2.4.1 · akvorado/akvorado
🩹 outlet: fix decoding of destination MAC address for sFlow 🩹 console: avoid clipped labels in Sankey graphs 🩹 console: fix empty widgets when toggling dark mode 🌱 outlet: improve BMP RIB performan...
github.com
July 14, 2026 at 2:21 PM
New release of Akvorado, a IPFIX/sFlow collector with a builtin web interface for visualization.

We are switching to CalVer for versioning. The GeoIP/networks database migrates from the orchestrator to the outlet. It is now possible to export enriched flows to Kafka.

github.com/akvorado/akv...
Release v2026.8.0 · akvorado/akvorado
Akvorado does not use the networks ClickHouse dictionary anymore. It is not removed on upgrade: it still holds a copy of the GeoIP databases in ClickHouse memory. Drop it on each cluster member onc...
github.com
August 12, 2026 at 7:15 AM
Router Flow Monitor is an eBPF-based network flow analysis agent for Linux routers. It collects per-flow traffic statistics with configurable sampling, enriches flows from a live BMP-fed RIB and/or MMDB ASN/city databases, and exports the results to Prometheus and IPFIX.
GitHub - stepbrobd/rfm: router flow monitor
router flow monitor. Contribute to stepbrobd/rfm development by creating an account on GitHub.
github.com
May 26, 2026 at 3:23 PM
First in pfsense:
- boot environment integration
- Kea integration
- Kernel WireGuard
- DCO for OpenVPN on FreeBSD
- A ton of work on pf, including:
- l2 filtering and plugging in dummynet
- nat64
- netflow/IPFIX output
- L2 cross connects
- tons of bugfixes
…
December 1, 2024 at 6:53 AM
This assumes that your router supports IPFIX (a lot of consumer-grade routers won't); I set my ISP's router to passthrough and ran my own pfSense router behind that.

All of which is massive overkill for < 10Mb. 🤷
January 1, 2025 at 2:05 PM
I'm surprised that flow-tools doesn't support v6. NetFlow v.9 did v6 flows ages ago.

If I were still writing NetFlow stuff, I'd make a small converter daemon from NetFlow/IPFix into protobufs, because the latter is really easy to work with.
November 21, 2024 at 9:44 PM
No problem, haven't looked at this in a while (got fiber ~4y ago and went a bit nuts playing with it).

Looks like the current advice is to run iperf3 on a couple of internal devices to generate traffic, then use Netflow/IPFIX monitoring on your router to measure the results.

1/
January 1, 2025 at 2:01 PM
NetObserv deploys an eBPF agent on every node to capture network flows, enrich them with Kubernetes metadata, and export to Loki, Prometheus, Kafka, or IPFIX — with a web console showing topology, raw flows, and traffic metrics

➜ https://ku.bz/STLN1Tks5
September 10, 2026 at 3:51 PM
Netdata v2.11.0

Summary; Highlights; Network Monitor Dashboard (Technical Preview); Network Flows: NetFlow, IPFIX and sFlow (Technical Preview); Network Topology and Application Dependencies (Technical Preview); SNMP Trap Listener; Expanded SNMP Device Coverage; Logs: OpenTelemetry Ingestion and…
Netdata v2.11.0
Summary; Highlights; Network Monitor Dashboard (Technical Preview); Network Flows: NetFlow, IPFIX and sFlow (Technical Preview); Network Topology and Application Dependencies (Technical Preview); SNMP Trap Listener; Expanded SNMP Device Coverage; Logs: OpenTelemetry Ingestion and a Unified Log…
whatsnew.fyi
August 19, 2026 at 8:00 AM
May 13, 2025 at 9:37 PM
February 14, 2025 at 10:17 PM
February 14, 2025 at 5:35 PM
I got a an MR merged in #Wireshark so that it now decodes the IPFIX packets sent to #PSKReporter correctly -- the issue had been bugging me for years, and I should have done the MR much sooner as it turned out to be a trivial fix!

Thanks to the maintainers...
December 29, 2024 at 10:08 PM
Fought the network monitoring wars - SNMP or NetFlow, which one saved my bacon?

#NetworkMonitoring #Snmp #Netflow #Ipfix

https://mustafaerbay.com.tr/en/blog/tutorials/ag-izlemede-snmp-mi-netflow-mu-secim-neden-tartismali-kalir/
SNMP or NetFlow in Network Monitoring: Why Does the Choice Remain
I delve into the unending debate between SNMP and NetFlow in network monitoring, drawing from my own experiences. I discuss when I chose which, the trade-offs.
mustafaerbay.com.tr
June 2, 2026 at 1:52 AM
Multiple CVEs patched across BGP, Flow Spec, Netflow v9, IPFIX, and packet handling. No exploitation in the wild confirmed — but upgrade immediately.

Thanks to Ryan Wilke at Lorikeet Security for the responsible disclosure.

→ fastnetmon.com/2026/05/27/f...
FastNetMon Advanced 2.0.380 | FastNetMon Official site
Release date: 27 May, 2026Version: 2.0.380 This release includes multiple security fixes and stability improvements across BGP, Flow Spec, Netflow v9, IPFIX, packet parsing, and internal buffer…
fastnetmon.com
May 28, 2026 at 11:00 AM
In production today with FastNetMon, FlowSpec plugs into disaggregated, carrier-grade setups:

- Telemetry (sFlow/IPFIX) exported at line rate
- FastNetMon detects anomalies in real time
- FlowSpec rules fire automatically at the edge
- Legitimate traffic keeps flowing
March 19, 2026 at 12:01 PM
FastNetMon + IP Infusion = automated DDoS defence on OcNOS.

Detect via sFlow/IPFIX. Mitigate via BGP Flow Spec or RTBH. Restore automatically when the attack stops.

Out-of-band. Disaggregated. Open standards end to end.

Solution brief → fastnetmon.com/2026/03/16/f...

#DDoS #BGP #NetworkSec
March 18, 2026 at 12:00 PM
🔹 Wykorzystanie danych NetFlow, sFlow i IPFIX do pasywnego monitorowania środowiska sieciowego — bez instalacji dodatkowych agentów.
May 16, 2025 at 6:40 AM
Open-source flow monitoring with SENSOR: Benefits and trade-offs

Flow monitoring tools are useful for tracking traffic patterns, planning capacity, and spotting threats. But many off-the-shelf solutions come with steep licensing costs and hardware demands, especially if you want…

#hackernews #news
Open-source flow monitoring with SENSOR: Benefits and trade-offs
Flow monitoring tools are useful for tracking traffic patterns, planning capacity, and spotting threats. But many off-the-shelf solutions come with steep licensing costs and hardware demands, especially if you want to process every packet. A research team at the University of Tübingen has built an alternative: an open-source, cost-effective, and distributed platform for collecting unsampled IPFIX data. Their system, called SENSOR, uses open-source software and vendor-agnostic components to monitor traffic at multiple points in the …
www.helpnetsecurity.com
August 15, 2025 at 3:17 AM