Network and security teams often need to distinguish suspicious activity from normal traffic while also investigating network or application performance deviations. That work depends on having relevant traffic and security data available for analysis.
Flowmon analyses network traffic and security data to detect threats and behavioural anomalies, investigate malicious activity and examine performance issues. It provides retained data and packet evidence for forensic analysis, alongside alerts and automated root-cause analysis for routine investigations.
Flowmon is useful for investigating suspicious network activity, including threat hunting and analysis of anomalous network or user behaviour. It also supports investigation of network and application performance deviations, using traffic data, alerts and automated root-cause analysis. Retained network security data and on-demand or on-event packet capture provide additional evidence for forensic work.
Flowmon is applicable across on-premises, public cloud, hybrid cloud, virtual, edge and branch-network environments. It can normalise proprietary and third-party data from diverse traffic environments and formats for analysis in one platform.
Gives security teams data to examine threats and anomalous network or user behaviour.
Provides alerts and traffic data for investigating network and application performance issues.
Keeps network security data available for later forensic analysis.
Automated root-cause analysis supports routine investigations of network and application issues.
Analyse network and security data to investigate potentially malicious activity.
Examine detected anomalies in network or user behaviour using available traffic data.
Investigate network and application performance deviations and their likely root causes.
Retrieve retained network security data and packet evidence for forensic analysis.
Normalise proprietary and third-party data from diverse traffic environments and formats.