You know that servers have log files and performance measuring tools and that traditional network devices have LEDs that blink when a port does something. You may have tools that tell you how busy an interface is, but mostly a network device is a black box. Network Flow Analysis opens that black box, demonstrating how to use industry-standard software and your existing hardware to assess, analyze, and debug your network. Unlike packet sniffers that require you to reproduce network problems in order to analyze them, flow analysis lets you turn back time as you analyze your network. You'll learn how to use open source software to build a flow-based network awareness system and how to use network analysis and auditing to address problems and improve network reliability. You'll also learn how to use a flow analysis system; collect flow records; view, filter, and report flows; present flow records graphically; and use flow records to proactively improve your network. Network Flow Analysis will show you how to: Identify network, server, router, and firewall problems before they become critical Find defective and misconfigured software Quickly find virus-spewing machines, even if they're on a different continent Determine whether your problem stems from the network or a server Automatically graph the most useful data And much more. Stop asking your users to reproduce problems. Network Flow Analysis gives you the tools and real-world examples you need to effectively analyze your network flow data. Now you can determine what the network problem is long before your customers report it, and you can make that silly phone stop ringing.
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
【One-Line Pitch】
A practical, Unix-flavored guide to building a flow-based network awareness system with open source tools, so you can diagnose yesterday's outage instead of waiting for users to reproduce it. Best for sysadmins and network administrators who already know their way around a command line.
【Book Arc】
- **Opening (~0%–10%)**: Frames the core problem — network devices are black boxes — and introduces flow analysis as a way to "turn back time" rather than chase reproducible packet captures. Also previews the reporting and filtering machinery to come.
- **Early (~10%–35%)**: Establishes fundamentals: what a flow actually is (shared source/destination addresses, ports, protocol), why long sessions are split into multiple records via timeouts, and why flow records are small, privacy-limited summaries rather than full packet contents. Introduces flow-tools as the standard free toolkit and its prerequisites (Unix-like OS, Perl editing, epoch time, gnuplot).
- **Middle (~35%–55%)**: Moves into implementation — collector and sensor architecture, installing flow-tools (with a warning against the buggy 0.68 release), configuring hardware flow export on Cisco and Juniper gear, and troubleshooting when no data reaches the collector.
- **Late (~55%–80%)**: Covers the analysis workflow: viewing, filtering, and reporting flows, including filter logic (protocols, ports, addresses, time, BGP), logical operators, and variable-driven filters. Reporting topics include default and customized reports, packet-size and flow-time distributions, and HTML output.
- **Ending (~80%–100%)**: Applies flow data to real operational goals — graphing useful data automatically, auditing, and proactively improving network reliability. (Excerpts do not cover the final chapters in detail.)
【Key Takeaways】
- **Flow analysis answers "who talked to whom, when, and how much"** (Early): flow records summarize every connection without capturing payload, making them compact and privacy-lighter than packet sniffers — three years of records fit in under 100GB in the author's data center.
- **Timeouts are the mechanism that makes flows useful in near real time** (Early): long-running sessions are broken into discrete records every few minutes, so you can spot a bandwidth-hogging download while it's still happening, not after it finishes.
- **The collector and sensors are the irreplaceable core** (Middle): you can analyze data in countless ways, but only after you gather and store it — so implementation starts with the collector, then the first sensor.
- **Version pitfalls are real** (Middle): flow-tools 0.68 corrupts data on 64-bit systems; use 0.68.5 or newer, and prefer packaged installs when available.
- **Hardware flow export is the simplest path** (Middle): most network hardware can report flows with only small overhead and no software installation; Cisco and Juniper are covered, but switches need different configuration than routers.
- **Troubleshooting follows a layered path** (Middle): use tcpdump to separate network problems from local software problems, check firewall rules and ports, then verify flow-capture configuration and permissions.
- **Filtering and reporting turn raw records into answers** (Late): filters by protocol, port, address, subnet, sensor, time, and BGP let you isolate the traffic that matters; variables and report types make recurring analysis repeatable.
- **The payoff is proactive operations** (Ending): flow data helps identify network, server, router, and firewall problems before they become critical, find misconfigured software and virus-spewing machines, and determine whether a problem is the network or a server.
【Reading Tips】
- **Deep-read the flow fundamentals and timeout sections** (Early): if you don't understand what a flow record actually contains and why sessions are split, the rest of the book becomes button-pushing.
- **Skim the installation and platform prerequisites** (Early–Middle) if you already run flow-tools; return when you hit a specific collector or sensor problem.
- **Treat the filtering and reporting chapters as a reference** (Late): the value is in the filter combinations and report types, not in reading them linearly.
- **Pay attention to the troubleshooting sequence** (Middle): the tcpdump-first approach is the most reusable operational habit in the book.
- **Take away the architecture, not just the commands**: collector + sensors + flow-tools + gnuplot is a pattern you can adapt to other flow tooling.
【Coverage Limits】
This guide is based on stratified excerpts covering roughly the first half of the book in detail, with later chapters represented mainly by table-of-contents entries and brief mentions. Specific final-chapter examples, advanced graphing recipes, and any material on NetFlow v8/v9 or IPFIX beyond passing references are not covered here.
k of repudiation state, “That problem was not the net- work.” Then think about doing all that by taking advantage of your existing equipment. 2 In t roduct i...
ces in the real world. I’ll start with the simplest network traffic, a ping request and response, and then proceed to more complicated examples of DNS and HT...
user running flow-capture can write files to that directory. Also check the system logs, such as /var/log/ messages, for error messages. (Remember, flow-capt...
stubbornly resist identification from the network, though: Some program on the host is using that port, and you’ll need to use that host’s native tools to id...
de the ICMP type and code as the destination port. A primi- tive that matches a particular type and code uses the ip-port primitive. ICMP type and code are u...
, ip-address-mask, and ip-address-prefix. Interface Filters Another way to filter by provider or network segment is to filter by the router interface. The ma...
it might appear that sorting by flows also sorts by bytes (octets) to a certain degree, but that’s illusionary. Here I report on the same data sorted by octe...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
Network Flow Analysis (Michael W. Lucas)(Z-Library)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
Network Flow Analysis (Michael W. Lucas)(Z-Library)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment