Skip to content
OBSERVE. ANALYZE. ACT.
Support Login

Flow-Records / NetFlow and IPFIX

Put flow intelligence within reach.

Generate flow records from observed traffic, process existing exporter feeds, and deliver telemetry through a controlled service path. 01Layer brings generation, template handling, transport conversion, and collector delivery together in NextIO.

Two supported paths: observed traffic through an IPFIX generator, or exporter records through a NetFlow proxy, delivered to configured collectors.
View the workflow at full size

Generate useful telemetry

Create flow records from a selected traffic feed.

Control the record path

Apply template-aware processing and configured transport handling.

Fit the collector

Define record format, addressing, transport, and downstream delivery.

Two starting points

Start with traffic or an existing exporter.

Choose a generator when the service starts from observed traffic. Choose a broker or proxy when upstream systems already produce NetFlow or IPFIX. Each role has its own controls.

Generate

Create IPFIX flow records

Configure collector address and protocol, observation identity, flow timeouts, and reporting behavior for the traffic entering the generator.

IPFIX Generator

Process

Handle exporter records

Use the NetFlow Proxy to process and edit flow records with template limits, field dictionaries, and a rules database.

NetFlow Proxy

Enrich the feed

Report DNS observations

DNS to JSON produces DNS telemetry as JSON or NetFlow/IPFIX records. Define collector delivery and DNS validation behavior for the service.

DNS to JSON

Reporting controls

Shape the record around the observation.

The IPFIX Generator exposes both collector delivery and flow lifecycle settings. These choices determine when a record is emitted and how a collector identifies the observation point.

Collector delivery
Select record format, destination IP, transport, collector port, and the UDP template refresh interval.
Observation identity
Set Observer ID and ingress and egress interface identifiers so records carry the intended collection context.
Flow lifecycle
Use the idle timeout to close inactive flows and the active reporting interval to report continuing activity.
Flow accounting
Set maximum concurrent flows, decide whether VLAN ID is part of the flow key, and choose uni-flow or bi-flow statistics.
Runtime behavior
Allocate compute resources and choose standalone activation or the documented HA/state-monitor activation mode.
IPFIX generator collector and flow reporting properties
Generator controls in NextIO. The displayed addresses and intervals are examples. View full size.

Template-aware processing

Give the collector records it can interpret.

Templates define the structure of NetFlow/IPFIX data. The processing path needs an explicit policy for template lifetime, unknown templates, and the fields it accepts.

NetFlow Proxy controls
ControlPurposeOperator check
Template lifetime and capacitySet expiry time, maximum templates, and maximum fields per template.Match expected exporter behavior and template refresh frequency.
Missing-template policyChoose whether to drop a flow set when its template is unavailable.Test exporter restart and collector reconnect scenarios.
Record verificationUse the configured template verification and field dictionary.Confirm that downstream systems decode the intended fields.
Rules databaseSelect the rules used to process or edit flow records.Compare representative input records with delivered output.
Non-flow trafficChoose the handling of traffic that is not recognized as NetFlow.Check that the source selection and drop policy agree.

Transport that fits the route

Connect across different delivery requirements.

The NetFlow/IPFIX service can extract records from TCP payloads, prepare UDP transport, and deliver records onward unchanged or converted back to TCP.

Exporter and collector connections

NetFlow TCP Server defines the listening port, framing structure, maximum connections, and conversion buffer. NetFlow TCP Client defines the receiving server address and port.

Use these components around the configured record-processing path when exporter and collector transport requirements differ.

TCP transport components

One-way telemetry transfer

IPFIX Message Broker extracts complete records and preserves the structure needed by collectors. The service can hand records to a UDP/Data Diode stage, with optional encryption and decryption.

The destination sender passes records onward or restores TCP delivery as required by the collector.

IPFIX Message Broker

Template refresh and successful collector decoding must be validated across the complete path, including any one-way or transport-conversion stage.

Operational workflow

Prove the record path from source to collector.

Keep generation settings, proxy behavior, and collector expectations aligned as the service grows.

  1. Identify the source role

    Select observed traffic for a generator, or identify the exporter connection and record format for a broker or proxy.

  2. Set the record and transport policy

    Configure observation identity, timeouts, template handling, processing rules, ports, and any conversion or one-way stage.

  3. Build and verify in NextIO

    Connect the required components, save the design, and run verification before starting or applying the service.

  4. Validate real records

    Check volume, record fields, template refresh, collector decoding, and activation behavior. Use captured evidence when transport or parsing needs investigation.

Keep exploring

From overview to operation.

Open the function descriptions, component controls, and related workflows behind this capability.

Connect flow telemetry to the teams that use it.

Discuss the sources, service requirements, and deployment that fit your operation.

Talk to our team