Skip to main content

Overview

The Monitoring Network Traffic Monitoring module provides deep visibility into traffic flows, bandwidth consumption, and protocol distribution across your virtual and physical networks. Operations teams use it to identify top bandwidth consumers, investigate anomalous patterns, and baseline normal network behavior.
Prerequisites

Network Traffic Views

Navigate to Monitor Center > Monitoring (Network section, admin view) to access network monitoring views.
Set the Scope filter to a specific project, network, or subnet to isolate traffic for a particular project or application tier.

Analyzing Traffic Anomalies

Review the Anomaly Detection panel

Navigate to Monitor Center > Monitoring (Network Anomaly, admin view). Monitoring uses behavioral baselines to flag traffic patterns that deviate significantly from historical norms.Each anomaly entry shows:
  • Detection time and duration
  • Affected host or network segment
  • Anomaly type (volumetric, port scan, protocol violation, etc.)
  • Confidence score

Drill into suspicious flows

Click on an anomaly event to view the associated flow records. Use the Flow Table to examine individual connections:

Correlate with logs

Cross-reference suspicious traffic with log events in the Log Explorer:
Combined network flow data and log events often confirm whether an anomaly is malicious or benign (e.g., a legitimate backup job generating unusual burst traffic).
Use Monitoring’s Linked Panels feature to open the Log Explorer pre-filtered to the host and time range of a network anomaly with a single click.

Setting Network Traffic Alerts

Alert on network conditions that indicate problems or security events:
Navigate to Monitor Center > Monitoring (Create Alert Rule, admin view):

Next Steps

Metrics & Alerts

Create bandwidth and packet loss alert rules

Log Analytics

Correlate network anomalies with log events from the same time window

Alert Rules (Advanced)

Configure compound alert conditions and escalation for network events

Monitoring Admin — DDoS Protection

Configure automatic DDoS mitigation policies (administrator)