Analytics
See your traffic clearly.
In real time.
Flowtriq gives you live PPS and BPS dashboards that update every second, historical views from 15 minutes to 365 days (or all-time), and protocol breakdowns that show exactly what kind of traffic is flowing through your infrastructure. No guessing, no waiting.
Live Dashboards
Streaming charts that keep pace with your traffic.
The Flowtriq dashboard shows packets per second and bits per second as they happen. Every data point arrives within one second of being measured on the server, so what you see on screen is what your infrastructure is handling right now.
Charts auto-scale to match your traffic volume. Whether you normally see 500 PPS or 500,000, the visualization adjusts so that spikes and dips are always visible at a glance.
Threshold lines overlay the live chart so you can see exactly how close your current traffic is to triggering a detection. When an incident opens, the chart highlights the affected time range automatically.
| Refresh interval | 1 second (streaming) |
| Primary metrics | PPS, BPS |
| Overlay indicators | Threshold line, incidents |
| Auto-scale | Yes, based on traffic volume |
| Scope | Per-node or workspace-wide |
4.8k | **
3.6k | ** **
2.4k | ** ** **
1.2k |** **** **
0 |______________________________
10:01 10:02 10:03 10:04
BPS: 168 Mbps | PPS: 4,812
Threshold: 12,306 PPS (3x p99)
Status: NORMAL
_
Historical Analysis
Zoom out to see the bigger picture.
Switch between 15-minute, 1-hour, 6-hour, 24-hour, 7-day, 30-day, 90-day, 365-day, and all-time views to analyze traffic patterns over time. Each time window aggregates data points into clean, readable charts without losing the detail that matters.
Historical views make it easy to spot recurring patterns. Maybe your traffic peaks every day at 2 PM, or maybe there is a weekly spike every Monday morning. Flowtriq helps you see those rhythms so you can plan capacity and set better thresholds.
Incidents are annotated directly on the historical timeline, making it simple to correlate traffic spikes with detected events. Click any incident marker to jump straight to its detail page.
| Time windows | 15m, 1h, 6h, 24h, 7d, 30d, 90d, 365d, all-time |
| Data granularity | 1s (15m), 5s (1h), 30s (6h), 2m (24h), aggregated (7d+) |
| Incident annotations | Clickable markers on timeline |
| Trend indicators | Rolling average overlay |
Peak PPS 12,491 at 14:22
Avg PPS 2,307
Min PPS 418 at 04:10
Peak BPS 412 Mbps
Avg BPS 78 Mbps
Incidents: 1 (14:22, UDP Flood)
Trend: +4.2% vs previous 24h
Protocol Breakdown
Know exactly what kind of traffic is flowing.
Flowtriq breaks down your traffic by protocol: TCP, UDP, and ICMP. This gives you a clear picture of your traffic composition at any point in time, and makes it obvious when the mix shifts unexpectedly.
A sudden jump in UDP percentage might indicate an amplification attack. An unusual ICMP spike could signal reconnaissance. Protocol breakdowns turn raw numbers into actionable context.
The breakdown is available on both live and historical views, so you can compare how your traffic composition changes throughout the day or during an incident.
TCP ████████████████████ 68.4% 3,292 PPS
UDP ████████ 26.1% 1,256 PPS
ICMP ██ 5.5% 264 PPS
Total: 4,812 PPS | 168 Mbps
Compared to 1h avg:
TCP 71.2% (-2.8%)
UDP 23.8% (+2.3%)
ICMP 5.0% (+0.5%)
Analytics Workflow
From raw data to clear insights
Collect: per-second metrics from every node
The FTAgent on each server reports PPS, BPS, and protocol stats every second. Data flows to the Flowtriq cloud where it is stored, indexed, and ready for visualization.
Visualize: live charts and protocol breakdowns
Data appears on your dashboard within one second of collection. Streaming charts, protocol pie charts, and per-node comparisons update continuously.
Analyze: spot trends and compare time windows
Switch between time ranges to compare today against yesterday. Overlay rolling averages to smooth out noise and reveal the underlying trends in your traffic.
Scope: per-node or workspace-wide views
View analytics for a single server, a group of nodes, or your entire workspace. Aggregated views make it easy to spot which node is handling the most traffic or which region is seeing unusual activity.
Export: download reports for your team
Export traffic data as CSV or JSON for use in your own tools, reports, or compliance documentation. Filter by time range, node, and protocol before exporting.
Why It Matters
Visibility changes everything
Flying blind
- No idea what normal traffic looks like
- Spikes discovered after users complain
- No protocol context during incidents
- Capacity decisions based on gut feeling
- No historical data for post-incident review
Flowtriq Analytics
- Clear picture of normal traffic baselines
- Spikes visible the second they happen
- Protocol breakdown reveals attack composition
- Capacity planning backed by real data
- Up to 365 days and all-time history for post-incident review
Traffic Intelligence
See who is talking and how much.
Traffic Intelligence gives you a fleet-wide view of your network activity. Identify top talkers by PPS and BPS across all nodes, track protocol breakdown trends over time, and spot anomalies with baseline deviation scoring.
Built for daily network operations, not just incident response. Use it to plan capacity, validate peering ratios, and understand how your traffic composition changes throughout the day.
| Top talkers | By PPS and BPS, all nodes |
| Protocol trends | TCP/UDP/ICMP over time |
| Utilization | Per-node bandwidth charts |
| Anomaly detection | Baseline deviation scoring |
| Composition | Real-time traffic donut |
nyc-edge-01 ████████████████████ 412 Mbps
fra-cdn-02 ████████████ 248 Mbps
sgp-api-03 ██████ 124 Mbps
Protocol: TCP 68% | UDP 26% | ICMP 6%
Deviation: within baseline
Transit Analytics
95th percentile billing and transit invoice verification.
Calculate burstable billing per node using industry-standard 95th percentile bandwidth measurement. Verify transit provider invoices against your own data, export to CSV for reconciliation, and track per-node bandwidth utilization with custom billing periods.
Transit Analytics uses the same per-second data collected by the agent, aggregated into billing-period views. Set custom date ranges that match your provider's billing cycle and compare your measured 95th percentile against what appears on the invoice.
| Billing method | 95th percentile (burstable billing) |
| Scope | Per-node transit usage with sparklines |
| Visualization | BPS distribution histogram with P95 annotation |
| Export | CSV export for invoice verification |
| Date ranges | Custom billing periods |
Node P95 BPS Peak
nyc-edge-01 312 Mbps 1.2 Gbps
fra-cdn-02 189 Mbps 804 Mbps
sgp-api-03 94 Mbps 412 Mbps
CSV Export Ready | 3 nodes | 30 days
Integrations
Export analytics to your existing stack
Prometheus / Grafana
- Scrape /api/metrics for per-node PPS, BPS, protocol breakdown
- Baseline deviation, active incidents, node status metrics
- Build custom Grafana dashboards from Flowtriq data
Terraform & REST API
- Manage nodes and channels via Terraform provider
- Full REST API for programmatic access to all data
- Infrastructure-as-code for enterprise deployments
FAQ
Common questions about analytics
How quickly does data appear on the dashboard?
Within one second. The FTAgent sends metrics every second, and the dashboard uses streaming updates so charts reflect the current state of your traffic with minimal delay.
Can I view analytics for all my nodes at once?
Yes. The workspace-wide view aggregates traffic across all nodes so you can see total PPS and BPS for your entire infrastructure. You can also filter down to individual nodes or compare them side by side.
What export formats are supported?
You can export traffic data as CSV or JSON. Both formats include timestamps, PPS, BPS, and protocol breakdowns. Filters for time range, node, and protocol are applied before export so you get exactly the data you need.
How far back does historical data go?
The dashboard provides views from 15 minutes up to 365 days and all-time. Short ranges show per-second resolution, while longer ranges aggregate to appropriate intervals. Data granularity scales with the time window: 1-second resolution for the 15-minute view, 5 seconds for 1 hour, 30 seconds for 6 hours, 2-minute intervals for 24 hours, and hourly aggregation for 7-day views and beyond.
Does analytics add any overhead to my servers?
No additional overhead. The FTAgent already collects PPS, BPS, and protocol stats for detection purposes. Analytics reuses the same data, so there is no extra sampling, no extra CPU usage, and no impact on your applications.
Can I set up automated reports or scheduled exports?
Yes. Enterprise customers can configure automatic nightly exports to an S3-compatible bucket. You can also use the REST API or Prometheus scrape endpoint to pull analytics data on any schedule you need for internal reporting.
Does analytics work for flow-only (no agent) nodes?
Yes. Flow-only nodes (sFlow, NetFlow, IPFIX) send traffic data to Flowtriq just like agent nodes. Analytics dashboards, protocol breakdowns, and historical views all work the same way. The only difference is that flow-only nodes report at the flow export interval rather than per-second.
Related Features
Analytics works hand in hand with
FAQ