Overview
The Monitoring Network Traffic Monitoring module provides deep visibility into traffic flows, bandwidth consumption, and protocol distribution across your virtual and physical networks. Operations teams use it to identify top bandwidth consumers, investigate anomalous patterns, and baseline normal network behavior.Prerequisites
- An active Polystack account with project access
- Network flow collection configured by your administrator (see Monitoring Admin — Agent Configuration)
Network Traffic Views
- Dashboard
- CLI
Navigate to Monitor Center > Monitoring (Network section, admin view) to access network monitoring views.
Analyzing Traffic Anomalies
Review the Anomaly Detection panel
Navigate to Monitor Center > Monitoring (Network Anomaly, admin view). Monitoring uses behavioral
baselines to flag traffic patterns that deviate significantly from historical norms.Each anomaly entry shows:
- Detection time and duration
- Affected host or network segment
- Anomaly type (volumetric, port scan, protocol violation, etc.)
- Confidence score
Drill into suspicious flows
Click on an anomaly event to view the associated flow records. Use the Flow Table
to examine individual connections:
Correlate with logs
Cross-reference suspicious traffic with log events in the Log Explorer:Combined network flow data and log events often confirm whether an anomaly
is malicious or benign (e.g., a legitimate backup job generating unusual
burst traffic).
Setting Network Traffic Alerts
Alert on network conditions that indicate problems or security events:- Bandwidth Threshold Alert
- Packet Loss Alert
Navigate to Monitor Center > Monitoring (Create Alert Rule, admin view):
Next Steps
Metrics & Alerts
Create bandwidth and packet loss alert rules
Log Analytics
Correlate network anomalies with log events from the same time window
Alert Rules (Advanced)
Configure compound alert conditions and escalation for network events
Monitoring Admin — DDoS Protection
Configure automatic DDoS mitigation policies (administrator)
