Network Telemetry — NetFlow, sFlow, IPFIX, and What a SOC Actually Watches

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Apr 27, 2026
11 min read
Read as

Last updated: May 1, 2026

100% Free

No signup. No paywall. No catch. One of our 10 most-requested practitioner modules — published in full so anyone can learn for free. We earn through consulting, not by gating knowledge.

See all 10 free modules →

Network telemetry is the per-flow metadata your routers and switches export — who talked to whom, when, how much, on what ports. NetFlow (Cisco), sFlow (broadcom/multivendor), IPFIX (the IETF standard) are the three protocols you will meet. PCAP captures everything; telemetry captures structured summaries that scale to enterprise traffic volumes. This module covers the protocol differences, what a SOC team actually does with telemetry, the modern enrichment stack (Zeek, Suricata, Elastic), and the operator checklist for getting useful telemetry without melting the network.

A SOC analyst with full PCAP for everything that flowed across the network would be in heaven and immediately also bankrupt — at terabytes per day, full PCAP is unaffordable beyond perimeter sensors. Telemetry is the structured-summary alternative: every flow becomes a row of metadata (source, destination, ports, bytes, packets, flags, timestamps), exported continuously, easily indexed and queried. This module is the working introduction to NetFlow / sFlow / IPFIX and how SOCs use them.

Why telemetry matters — the volume and visibility tradeoff

Full PCAP at 10 Gbps = 4.5 TB/hour. Storing days or weeks is six-figure infrastructure. Telemetry — one row per flow rather than every packet — typically reduces storage by 100-1000x while keeping the questions a SOC actually asks: who talked to whom, when, how much, what protocol, was it accepted or rejected.

What you losepayload content, exact packet timing, application-layer evidence.

What you keepcomplete connection-level visibility for forensics, baseline traffic patterns, anomaly detection signals.

The operating principletelemetry everywhere; selective PCAP at perimeter and high-value sensors; Zeek/Suricata logs everywhere on critical segments. The combination — telemetry for breadth, PCAP for depth, NIDS logs for signal — is the modern SOC visibility stack.

Want this for your team?

Custom team training + practitioner advisory

Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.

Book team training call Replies in 4 working hrs · India-only · Senior consultants