Introduction

NetFlow data describes network traffic using technical attributes such as IP addresses, ports, interfaces, AS numbers, and DSCP values. Grouping lets you associate these technical attributes with meaningful business labels.

For example, you can define a portion of your network, such as the 10.20.0.0/16 subnet or any interface whose name starts with Gi0/, and associate it with a group such as Finance or Branch Office. OpsRamp then labels matching NetFlow traffic with the configured group name. This lets you view and compare traffic by business dimensions such as department, location, application, and security zone instead of relying only on raw network addresses.

Grouping is part of NetFlows and is configured from the Grouping tab in Netflows Configurations.

Intended users: Network administrators and NOC engineers who manage NetFlow monitoring and need to analyze traffic by business unit, site, application, or security zone.

Common use cases include:

  • Measuring bandwidth by department.
  • Comparing traffic between sites.
  • Monitoring traffic between security zones.
  • Measuring traffic to cloud providers.

See Use Cases for configuration examples.

Key Concepts

TermMeaning
CriterionA named, reusable rule that describes a network attribute. For example, Finance subnets can represent an IP Address criterion, while Web ports can represent a Port criterion. A criterion has one Type and one or more Definitions.
DefinitionA matching rule within a criterion. A definition consists of a definition type and value, such as IPv4 CIDR 10.20.0.0/16, Range 8080 to 8090, or Regex ^Gi0/. A criterion matches when any one of its definitions matches.
GroupA named label, such as Finance, that is applied to matching NetFlow traffic. A group has one Group Type and one or more criteria.
Group TypeThe business dimension associated with a group, such as Department or Location. Group types let you view groups of the same category together.

Criteria are shared and reusable. You can use the same criterion in multiple groups. Changes to a criterion apply to every group that uses the criterion.

How Traffic Is Matched to a Group

OpsRamp evaluates each NetFlow record against the configured groups using the following rules:

  1. Definitions within a criterion use OR logic. A criterion matches when any one of its definitions matches. For example, a criterion containing the CIDRs 10.20.0.0/16 and 10.30.0.0/16 matches addresses in either subnet.
  2. Criteria within a group use AND logic. A group matches only when every criterion in the group matches. For example, a group containing an IP Address criterion for 10.20.0.0/16 and a Port criterion for 443 matches only HTTPS traffic for that subnet. It does not match all traffic for the subnet or all HTTPS traffic.
  3. Source and destination are evaluated separately. A flow can belong to one group as its source and another group as its destination. For a group to match on one side of the flow, all criteria in the group must match on that same side.
  4. A flow can belong to multiple groups. If a flow matches multiple groups of the same group type, OpsRamp labels the flow with all matching groups.

The following table shows the flow attribute evaluated for each criterion type:

Criterion typeSource sideDestination side
IP AddressSource IP addressDestination IP address
PortSource portDestination port
InterfaceInput (ingress) interface nameOutput (egress) interface name
ASNSource AS numberDestination AS number
DSCPDSCP value of the flowDSCP value of the flow
ExporterExporter that sent the flowExporter that sent the flow

Example

A group named Finance with the group type Department contains an IP Address criterion with the CIDR 10.20.0.0/16.

FlowSource groupDestination group
10.20.4.15 → 8.8.8.8FinanceNone
172.16.1.9 → 10.20.7.2NoneFinance
10.20.4.15 → 10.20.7.2FinanceFinance
172.16.1.9 → 8.8.8.8NoneNone

Prerequisites

Before configuring groups, ensure that the following requirements are met:

  • You have the NPM_Manage permission. Without this permission, Configurations is not displayed on the Net Flows dashboard.
  • NetFlow data is already being sent from an NPM Collector to OpsRamp.
  • Each client can have up to 20 criteria and 20 groups.
  • A group can contain up to 6 criteria, with one criterion for each criterion type.
  • IP Address criteria support IPv4 addresses only.

Access the Grouping Page

  1. Navigate to Infrastructure > Net Flows. The NPM dashboard opens.
  2. Select Configurations. The Netflows Configurations panel opens.
  3. Select the Grouping tab. The Grouping page opens.

The Grouping page contains the following areas:

  • Grouping pane: The left pane lists configured groups. Each group displays its name and group type. Use the search icon to find a group by name, or select + to create a group. If no groups are configured, the pane displays No groups found.
  • Criteria view: Select All Criteria in the Grouping pane to display all configured criteria. Select a group to display only the criteria associated with that group.

Manage Criteria

View Criteria

The All Criteria view displays the following information:

ColumnDescription
CriterionName of the criterion.
TypeCriterion type: IP Address, Interface, DSCP, Exporter, Port, or ASN.
DefinitionsDefinition types used by the criterion. The number in parentheses indicates the number of definitions of that type. For example, IPv4 CIDR (2) indicates two IPv4 CIDR definitions.
GroupsNumber of groups that use the criterion. Hover over the number to view the group names.

From this view you can:

  • Select ADD to create a criterion.
  • Search for a criterion by name.
  • Use All Types to display criteria for selected types.
  • Select REFRESH to reload the list.
  • Display 20, 50, or 100 rows per page and use the pagination controls to navigate between pages.

If no criteria are configured, the view displays No criteria found.

Add a Criterion

  1. From the All Criteria view, select ADD. The Add Criteria window opens.
  2. From Type, select the criterion type.
  3. In Criterion, enter a name for the criterion.
  4. Under DEFINITIONS, select + DEFINITION, and then select a definition type. For ASN, a definition row is added directly because ASN has only one definition type.
  5. Enter the value for the definition.
  6. Repeat steps 4 and 5 to add additional definitions. The criterion matches when any one of its definitions matches.
  7. Select ADD CRITERIA.

The DEFINITIONS section becomes available after you select a Type and enter a Criterion name. ADD CRITERIA becomes available after all definitions contain valid values.

Definition Types and Valid Values

Criterion typeDefinition typeWhat to enterExampleValidation message
IP AddressIPv4 addressA single IPv4 address.192.168.1.10Invalid IPv4 address (e.g. 192.168.1.1)
IP AddressIPv4 CIDRA network in CIDR notation, prefix 0 to 32.10.20.0.0/16Invalid CIDR (e.g. 10.0.0.0/24, prefix 0-32)
IP AddressIPv4 rangeA Start IP and an End IP. The start must not be greater than the end.10.1.1.1 to 10.1.1.50Start IP must be ≤ end IP
IP AddressIPv4 RegexA regular expression matched against the IP address text.^10\.20\.Invalid regular expression
InterfaceNameThe exact interface name.GigabitEthernet0/1—
InterfaceRegexA regular expression matched against the interface name.^Gi0/Invalid regular expression
DSCPNamed ValueSelect a DSCP class from the list: DF, BE, EF, VA, LE, CS0 to CS7, or AF11 to AF43.EF (46)—
DSCPNumericA DSCP value from 0 to 63.46DSCP numeric value must be 0-63
ExporterIP addressThe IP address of the exporter.10.0.0.1—
ExporterHostnameThe hostname of the exporter.core-rtr-01Invalid hostname
PortNumberA single port from 0 to 65535.443Port must be 0-65535
PortRangeA Start port and an End port. The start must not be greater than the end.8080 to 8090Start port must be ≤ end port
ASNAS NumberAn AS number from 1 to 4294967295.16509ASN must be 1-4294967295

View or Edit a Criterion

  1. In the All Criteria view, hover over the criterion row and select the ⋯ (more) icon.

  2. Select View details. The Edit - window opens.

  3. Modify the Criterion name or definitions as required. You cannot change the Type.

  4. Select SAVE.

If the criterion is used by multiple groups, OpsRamp displays:

This criterion is added to multiple groups. Saving will apply changes to all.

Select YES to apply the changes to all groups that use the criterion, or select NO to return without saving.

Copy a Criterion

Use Copy to create a criterion using the values of an existing criterion as the starting point.

  1. Hover over the criterion row, select ⋯, and then select Copy. The Copy - window opens with the existing values.
  2. Enter a new name in Criterion, and modify the type or definitions as required.
  3. Select COPY.

Remove a Criterion

  1. Hover over the criterion row, select ⋯, and then select Remove.
  2. Confirm the removal.

You cannot remove a criterion that is used by a group. For these criteria, Remove is unavailable and the following tooltip identifies the groups using the criterion:

This criterion is associated with the following groups. To proceed with removal, first unmap it from these groups.

Remove the criterion from the associated groups before removing it. See View or Edit a Group.

Manage Groups

Group Types

Every group belongs to one of the following group types. You cannot change the group type after creating the group.

Group typeTypical use
DepartmentBusiness units, such as Finance, HR, or Engineering.
LocationPhysical sites, such as London HQ or Pune Branch.
ApplicationBusiness applications or services, such as CRM or Voice.
Security ZoneNetwork zones, such as DMZ, Internal, or Guest.
ConnectivityLink types, such as WAN, LAN, MPLS, or Internet.
EnvironmentDeployment environments, such as Production, Staging, or Development.
Cloud ProviderPublic cloud providers.
Site TypeTypes of sites, such as Data Center, Branch, or Remote Office.
Compliance ZoneRegulated areas of the network, such as PCI or HIPAA.

Create a Group

  1. From the Grouping pane, select +. The Add Group window opens.
  2. Under GROUP DETAILS:
    • In Name, enter a name for the group.
    • From Type, select a group type.
  3. Under CRITERIA, select + CRITERIA TYPE. This option becomes available after you enter a Name and select a Type. The Add Criteria window opens.
  4. From Type, select a criterion type. Criterion types that are already used by the group are not displayed because a group can contain only one criterion of each type.
  5. In Criterion, do one of the following:
  • Use an existing criterion: Select a criterion from the list. Its definitions are displayed for reference and cannot be modified from this window. To modify the definitions, see View or Edit a Criterion.
  • Create a criterion: Select + ADD from the list, enter a name, and select ADD CRITERIA. Add definitions under DEFINITIONS as described in Add a Criterion. If no criteria exist for the selected type, enter the name directly in Criterion.
  1. Select ADD CRITERIA. The criterion is added to the group as a card displaying its name, type, and definitions.
  2. Repeat steps 3 through 6 to add criteria of other types. Traffic must match all criteria within a group.
  3. Select ADD GROUP.

The new group appears in the Grouping pane.

To remove a criterion from the group before you save it, select the X icon on its card.

View or Edit a Group

  1. In the Grouping pane, hover over the group and select the ⋯ (more) icon.

  2. Select View details. The group opens.

  3. Make the required changes:

    • Change the Name. The Type cannot be changed.
    • Select + CRITERIA TYPE to add a criterion of a type that the group does not use yet.
    • On a criterion card, select ⋯ > Remove to take that criterion out of the group. The criterion itself stays in All Criteria.
  4. Select SAVE.

Rename a Group

  1. In the Grouping pane, hover over the group, select ⋯, and then select Rename.
  2. In Group Name, enter the new name.
  3. Select SAVE.

Remove a Group

  1. In the Grouping pane, hover over the group, select ⋯, and then select Remove.
  2. In the confirmation message This group will be removed permanently., select REMOVE.

Removing a group does not remove its criteria. The criteria remain in All Criteria and can be used in other groups.

View Grouped Traffic

After traffic is labeled, group types become available as Group By fields on the NPM dashboard.

  1. Navigate to Infrastructure > Net Flows.
  2. Select a time range of 8 hours or less.
  3. In Group By, select a group field. Each group type has two fields:
  • Source <Group Type>, such as Source Department, identifies the group associated with the source of the traffic.
  • Destination <Group Type>, such as Destination Department, identifies the group associated with the destination of the traffic.
  1. To view the amount of traffic sent by each group, select only a Source field.
  2. To view traffic between groups, select both a Source and Destination field, such as Source Department and Destination Department.

The chart and corresponding table update to display traffic based on the selected group fields.

Filter Traffic by Group

You can use group fields in the Query on the NPM dashboard to display traffic associated with selected groups.

  1. Navigate to Infrastructure > Net Flows.
  2. Select a time range of 8 hours or less.
  3. In Query, enter a condition that uses a group field. Enter the field name as it appears in Group By and specify the group name in double quotation marks.
  4. Apply the query. The dashboard displays only the matching traffic.

Group fields support the following operators:

=, !=, IN, NOT IN, CONTAINS, NOT CONTAINS, STARTS WITH, NOT STARTS WITH, ENDS WITH, and NOT ENDS WITH.

Combine multiple conditions using AND and OR.

Example Queries

QueryResult
Source Department = "Finance"Traffic sent from the Finance group.
Destination Location IN ("London", "Pune")Traffic sent to the London or Pune groups.
Source Security Zone = "Guest" AND Destination Security Zone = "Cardholder Data"Traffic from the Guest zone to the Cardholder Data zone.
Source Department = "Finance" AND protocol = "TCP"TCP traffic sent from the Finance group.

Where Else You Can Use Group Fields

Group fields such as Source Department and Destination Location can be used wherever NetFlow data is filtered or grouped.

FeatureHow to use group fieldsMore information
Custom MetricsSelect group fields in Filter Query to measure only the traffic of selected groups, and in Group By to get one value per group.Netflows Configurations
AlertsAlerts that are based on a Custom Metric use the group fields of that metric, so you can be alerted about the traffic of a specific group, for example when Source Department = "Finance" exceeds a threshold.Netflows Configurations
NetFlows tile (Dashboard 2.0)In Tile Options, select group fields in +QUERY to filter the tile, and in GROUP BY to show traffic by group.NetFlows Tile
Netflow Insights reportSelect group fields in the report filters and grouping options to report traffic by group.Netflow Insights

Use Cases

The following examples identify the criteria and groups to create and the Group By fields to select on the NPM dashboard. Replace the example addresses and values with values appropriate for your environment.

Select a time range of 8 hours or less when viewing the results.

Measure Bandwidth by Department

Goal: Determine how much traffic each department generates.

CriterionTypeDefinitions
Engineering subnetsIP AddressIPv4 CIDR 10.10.0.0/16, IPv4 CIDR 10.11.0.0/16
Finance subnetsIP AddressIPv4 CIDR 10.20.0.0/16
Sales subnetsIP AddressIPv4 range 10.30.0.1 to 10.30.3.254
GroupGroup TypeCriteria
EngineeringDepartmentEngineering subnets
FinanceDepartmentFinance subnets
SalesDepartmentSales subnets

View the result: Group By Source Department to rank departments by the traffic they send. Add Destination Department to see traffic between departments.

Understand Traffic Between Sites

Goal: Identify which offices exchange the most traffic, for example, before resizing WAN links.

CriterionTypeDefinitions
London addressesIP AddressIPv4 CIDR 10.100.0.0/16
Pune addressesIP AddressIPv4 CIDR 10.200.0.0/16
WAN interfacesInterfaceRegex ^Gi0/
GroupGroup TypeCriteria
LondonLocationLondon addresses
PuneLocationPune addresses
WANConnectivityWAN interfaces

View the result: Group by Source Location and Destination Location to view traffic between offices. Group by Source Connectivity to view the amount of traffic entering through WAN interfaces.

Watch Traffic Between Application Tiers

Goal: Verify that web servers reach databases only through the application tier.

CriterionTypeDefinitions
Web serversIP AddressIPv4 CIDR 10.50.1.0/24
App serversIP AddressIPv4 CIDR 10.50.2.0/24
DB serversIP AddressIPv4 CIDR 10.50.3.0/24
GroupGroup TypeCriteria
Web TierApplicationWeb servers
App TierApplicationApp servers
DB TierApplicationDB servers

View the result: Group by Source Application and Destination Application. Traffic from Web Tier to DB Tier identifies direct access that bypasses the application tier.

Monitor Traffic Between Security Zones or Environments

Goal: Verify that zones that must remain separate do not exchange traffic, such as a cardholder-data zone and guest network, or staging and production environments.

CriterionTypeDefinitions
Cardholder data networkIP AddressIPv4 CIDR 10.60.0.0/24
Guest networkIP AddressIPv4 CIDR 192.168.100.0/24
Production subnetsIP AddressIPv4 CIDR 10.70.0.0/16
Staging subnetsIP AddressIPv4 CIDR 10.71.0.0/16
GroupGroup TypeCriteria
Cardholder DataSecurity ZoneCardholder data network
GuestSecurity ZoneGuest network
ProductionEnvironmentProduction subnets
StagingEnvironmentStaging subnets

View the result: Group by Source Security Zone and Destination Security Zone, or by Source Environment and Destination Environment. Traffic between zones that must remain separate appears as a link between those groups.

To display only this traffic, use a query such as:

Source Security Zone = "Guest" AND Destination Security Zone = "Cardholder Data"

Measure Traffic to Cloud Providers and Partners

Goal: Determine how much traffic is exchanged with each cloud provider or partner network identified by its AS number.

CriterionTypeDefinitions
Amazon ASNASNAS Number 16509
Microsoft ASNASNAS Number 8075
Google ASNASNAS Number 15169
GroupGroup TypeCriteria
AWSCloud ProviderAmazon ASN
AzureCloud ProviderMicrosoft ASN
Google CloudCloud ProviderGoogle ASN

View the result: Group by Destination Cloud Provider to view traffic sent to each provider. Group by Source Cloud Provider to view traffic received from each provider.

Check DSCP Markings for Voice Traffic

Goal: Verify that traffic from IP phones contains the expected DSCP marking, such as EF (46).

CriterionTypeDefinitions
Voice VLANIP AddressIPv4 CIDR 10.80.0.0/22
GroupGroup TypeCriteria
VoiceApplicationVoice VLAN

View the result: Group by Source Application and dscp. Traffic from the Voice group that is not marked EF indicates where the QoS marking is missing.

Compare Traffic by Site Type

Goal: Compare traffic across different site types, for example, before deploying a new service to all stores.

CriterionTypeDefinitions
Store networksIP AddressIPv4 CIDR 10.128.0.0/10
Warehouse networksIP AddressIPv4 CIDR 10.192.0.0/12
Head office networkIP AddressIPv4 CIDR 10.1.0.0/16
GroupGroup TypeCriteria
StoresSite TypeStore networks
WarehousesSite TypeWarehouse networks
Head OfficeSite TypeHead office network

View the result: Group by Source Site Type to compare the traffic sent by each type of site.

When Changes Take Effect

The NPM Collector applies groups to traffic as the traffic is received. The collector loads the grouping configuration from OpsRamp when it starts and refreshes the configuration once every 24 hours by default.

  • After you create, edit, or remove a group or criterion, allow up to 24 hours for the change to appear in NetFlow data.
  • Grouping applies only to traffic received after the collector loads the change. Previously received traffic retains the group labels assigned when the traffic was received and is not relabeled.
  • If you rename a group, traffic received before the change retains the previous group name. If the selected time range spans the change, both the previous and new group names can appear in the results.
  • If you remove a group, traffic received before the change continues to display that group.

Troubleshooting

What you seePossible causeWhat to do
Configurations is not displayed on the Net Flows dashboard.You do not have the NPM_Manage permission.Ask your administrator for the NPM_Manage permission.
A new or edited group does not appear in NetFlow data.The collector has not refreshed its grouping configuration.Wait up to 24 hours after making the change.
Older traffic does not display a new group.Grouping is not applied to traffic received before the change.This behavior is expected. Only new traffic is labeled.
A group does not match any traffic.The group contains multiple criteria and no single flow matches all criteria on the same side.Review the criteria in the group. To match traffic against any of several values, add those values as definitions within one criterion instead of creating separate criteria.
Remove is unavailable for a criterion.The criterion is used by one or more groups.Remove the criterion from those groups first.
You cannot add another criterion or group.The client has reached the limit of 20 criteria or 20 groups.Remove criteria or groups that are no longer required.
+ CRITERIA TYPE is unavailable in the group window.Name or Type is empty, or the group already contains a criterion for every type.Enter a Name and select a Type.
The total traffic across all groups is greater than the total traffic.Some traffic belongs to multiple groups of the same type and is counted under each matching group.This behavior is expected. To avoid it, ensure that groups of the same type do not overlap.
An Interface or Regex criterion matches too much traffic or does not match any traffic.Regex matches anywhere within the text and is case-sensitive. Interface Name must match exactly.Anchor the regular expression using ^ and $, and verify the spelling and capitalization of interface names.
The selected time range is too large for the field(s) appears when you use a group field.Group fields are available only for time ranges of 8 hours or less.Select a time range of 8 hours or less.
Group fields are not listed in Group By.No labeled traffic has been received yet.Wait for the collector to load the grouping configuration and for new traffic to arrive. See When Changes Take Effect.