> For the complete documentation index, see [llms.txt](https://docs.eseye.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.eseye.com/api-reference/connectivity-metrics/traffic-flow-netflow-metrics.md).

# Traffic flow (NetFlow) metrics

Analyse device traffic metadata with NetFlow records.

Traffic flow metrics describe device communication after a network session has been established.

> **Question answered:** Where did the device send traffic, and how much?

### What the records show

* Source and destination IP addresses.
* Ports and protocols.
* Traffic volumes and packet counts.
* High-level application classification, where available.

> **Privacy boundary:** Traffic flow data contains metadata only. It does not include packet payloads.

### Metadata only

NetFlow records contain metadata about traffic. They do not contain packet payloads, and the service does not perform deep application-layer inspection. You can see that a device sent a given volume of traffic to a given endpoint over a given protocol. You cannot see the contents of that traffic, by design. Scope and boundaries covers this in full.

### Common uses

* **Understanding traffic destinations:** Seeing the actual endpoints a fleet talks to often surfaces services nobody remembered were still in the picture.
* **Identifying unexpected or unauthorised endpoints:** Traffic to an endpoint outside your approved list is visible without needing anything installed on the device.
* **Traffic volume and behaviour analysis:** Volumes and packet counts per flow show how consumption is distributed across destinations, which is usually more useful than a single per-SIM total.
* **Security posture validation:** The practical version of the question is simple: are these devices only talking to the services they are supposed to talk to? NetFlow data answers it directly, which is why this dataset commonly feeds SIEM and SOC environment


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.eseye.com/api-reference/connectivity-metrics/traffic-flow-netflow-metrics.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
