Last updated: May 1, 2026
A SOC analyst with full PCAP for everything that flowed across the network would be in heaven and immediately also bankrupt — at terabytes per day, full PCAP is unaffordable beyond perimeter sensors. Telemetry is the structured-summary alternative: every flow becomes a row of metadata (source, destination, ports, bytes, packets, flags, timestamps), exported continuously, easily indexed and queried. This module is the working introduction to NetFlow / sFlow / IPFIX and how SOCs use them.
Why telemetry matters — the volume and visibility tradeoff
Full PCAP at 10 Gbps = 4.5 TB/hour. Storing days or weeks is six-figure infrastructure. Telemetry — one row per flow rather than every packet — typically reduces storage by 100-1000x while keeping the questions a SOC actually asks: who talked to whom, when, how much, what protocol, was it accepted or rejected.
What you losepayload content, exact packet timing, application-layer evidence.
What you keepcomplete connection-level visibility for forensics, baseline traffic patterns, anomaly detection signals.
The operating principletelemetry everywhere; selective PCAP at perimeter and high-value sensors; Zeek/Suricata logs everywhere on critical segments. The combination — telemetry for breadth, PCAP for depth, NIDS logs for signal — is the modern SOC visibility stack.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.