Skip to content
FirstSIDocs

Workstation network flows

Every connection a workstation or server makes, with the process, the user, the destination and the volume.

The agent's NetFlow module records every network connection made by the workstation, with the process, the user, the destination, the port and the volume exchanged. You can see who talks to whom, and with which software.

The screens

ScreenUse
Network Flows (#/flows)The list of connections. Filters: text, protocol (TCP/UDP), direction, machine, dates; Hide listening sockets checkbox
Devices (#/devices)The machines with an agent. A machine's page has Timeline, Applications, Destinations, Alerts, Network and Installs tabs
Destinations (#/destinations)The destinations contacted; Watch turns one into a monitor
Network View, Metrics, Service MapVolumes, trends, who serves what
DNS MappingsNames matched to IP addresses
Filter templatesPrivacy rules per operating system type (administrators)

To cross-check workstations, gateways and the firewall over a period, the Flow explorer is the better tool. To learn everything about one IP address, go through Investigate a device.

One trap to know about: without dates, the text search only covers the last 24 hours (the screen says so). Pick a period to go further back.

Exporting

Export produces a CSV of up to 500,000 rows, over at most 30 days.

Actions on a machine

A machine's page offers Export, Test connectivity, Force sync, Generate PDF report and Restart agent. Delete device is for administrators only.

What the agent collects

With NETFLOW=true, the agent sends connections aggregated over 30 s, DNS queries (which feed DNS Monitor), Wi-Fi, system metrics and installs. Latency measurement and subnet, domain or process filters are off by default.

Alerts

NetFlow rules (volume, port scan, new process, unusual hours, suspicious destination, frequency) are managed in Alerts. They are checked every minute.

Retention

Flows follow the customer's retention period: 90 days by default, if automatic purge is on. The hourly totals used by Metrics are kept for 60 days.

Source: · FirstSI Docs · updated 2026-10-10