NetFlow and Metadata Generation

Extract and deliver optimized network data to your tools, improving performance and threat detection.

Flow Data: Gain Insights. Take Action.

As chipset capacity increases, security and monitoring tools are being forced to process more and more data, which overloads the tools. The solution? Metadata.

With NetFlow and Metadata Generation, enterprises can:

  • Extract and deliver only relevant data to your tools, such as SIEMs, reducing their load and improving efficacy. 
  • Detect threats faster by analyzing metadata versus raw packet streams
  • Overcome limited reach of security tools that may not have access to all the valuable information in the network by sending them summary information
  • Separate signal from noise and help reduce false positives by the tools


What is metadata?

Metadata is data about data that describes and summarizes information about your raw network packets (based on Layer-4 and Layer-7 information), such as: 

  • Summary statistic information about network traffic flows
  • Critical details about the flow (5-tuple, protocol information)
  • Application-level insights based on Layer-7 traffic information to enable successful analysis across on-premises and public cloud infrastructures.

The Gigamon Metadata Generation capability supports CEF and NetFlow, a network protocol that is used to collect statistics on IP traffic information such as IP source, destination of traffic, class of service, causes of congestion, etc. NetFlow is a specific, standard form of metadata that provides visibility into traffic types and usage patterns across systems, enabling enterprises to catch denial of service attacks, data extraction, and other events that represent a security risk.

Gigamon has also extended Netflow Generation to include IPFIX, enabling application-specific extensions, as well as standard traffic information across on-premises and public cloud environments.

By offloading metadata generation to the Gigamon Visibility Platform, enterprises can leverage their valuable production network and security tools, such as SIEMs, more efficiently by cutting through the noise and sending only relevant data to them.


