Workstation network flows
Every connection a workstation or server makes, with the process, the user, the destination and the volume.
The agent's NetFlow module records every network connection made by the workstation, with the process, the user, the destination, the port and the volume exchanged. You can see who talks to whom, and with which software.
The screens
| Screen | Use |
|---|---|
Network Flows (#/flows) | The list of connections. Filters: text, protocol (TCP/UDP), direction, machine, dates; Hide listening sockets checkbox |
Devices (#/devices) | The machines with an agent. A machine's page has Timeline, Applications, Destinations, Alerts, Network and Installs tabs |
Destinations (#/destinations) | The destinations contacted; Watch turns one into a monitor |
| Network View, Metrics, Service Map | Volumes, trends, who serves what |
| DNS Mappings | Names matched to IP addresses |
| Filter templates | Privacy rules per operating system type (administrators) |
To cross-check workstations, gateways and the firewall over a period, the Flow explorer is the better tool. To learn everything about one IP address, go through Investigate a device.
One trap to know about: without dates, the text search only covers the last 24 hours (the screen says so). Pick a period to go further back.
Exporting
Export produces a CSV of up to 500,000 rows, over at most 30 days.
Actions on a machine
A machine's page offers Export, Test connectivity, Force sync, Generate PDF report and Restart agent. Delete device is for administrators only.
What the agent collects
With NETFLOW=true, the agent sends connections aggregated over 30 s, DNS queries (which feed DNS Monitor), Wi-Fi, system metrics and installs. Latency measurement and subnet, domain or process filters are off by default.
Alerts
NetFlow rules (volume, port scan, new process, unusual hours, suspicious destination, frequency) are managed in Alerts. They are checked every minute.
Retention
Flows follow the customer's retention period: 90 days by default, if automatic purge is on. The hourly totals used by Metrics are kept for 60 days.
Source: · FirstSI Docs · updated 2026-10-10