Wansight is the visibility half of Wanguard: the same Flow and Packet Sensors, the same multi-tenant Console, without DDoS detection and mitigation. Deep traffic inspection, flow- and packet-level accounting and high-resolution bandwidth monitoring for NOC and IT operations teams — and when you need the protection later, a Wanguard license key upgrades the same installation, no reinstall.
Wanguard overviewWansight licenses
$345 / year per Sensor · Console free · upgrades to Wanguard with a key
Collected telemetry is aggregated into detailed reports, time-series graphs and top lists — traffic distribution, protocol usage, host behavior, application performance — for capacity planning and the fast diagnosis of network problems.
Per-IP, per-subnet and per-IP-group graphs for 50+ traffic decoders, from TCP flags to QUIC, DNS, NTP and the streaming platforms; tops for talkers, external IPs, autonomous systems, countries, ports and protocols; accounting you can bill from, with 95th-percentile values.
Reports in the Wansight guide →Reports from the last five seconds to the last ten years; the Flow Collector stores, searches, filters and exports flows — with Sankey, heatmap and stacked flow graphs from ClickHouse — and the Packet Tracer captures dumps you read in a Wireshark-like page, hex and ASCII included.
Flows and packets in the guide →The multi-tenant Console gives NOC, IT operations, customers and departments their own dashboards and their own slice of the traffic — SAML, LDAP and RADIUS for sign-in, white-label branding, and any report emailed on a schedule as PDF or Excel.
The Console in detail →Need DDoS detection and automatic mitigation? That is Wanguard — same Sensors, same Console, plus the anomaly engine, the responses and the Filter.
What the traffic monitoring and analysis tool reads — flows and port-mirrored packets — and where Wanguard goes further.
Andrisoft Wansight is an enterprise-grade Linux-based monitoring platform that provides NOC / IT operations teams with a unified environment for comprehensive network visibility. Unlike Wanguard, it does not incorporate DDoS detection and mitigation capabilities.
Wansight utilizes the Flow Sensor and Packet Sensor modules to perform deep traffic inspection, flow and packet-level accounting, and high-resolution bandwidth monitoring. The Flow Sensor processes NetFlow, IPFIX, and sFlow data, while the Packet Sensor captures traffic from in-line interfaces, TAPs, and port-mirroring configurations at wire speed. Collected telemetry is aggregated and processed to generate detailed reports, time-series graphs, and top lists, enabling accurate analysis of traffic distribution, protocol usage, host behavior, and application performance. This information supports data-driven capacity planning and facilitates rapid diagnosis of network performance issues.
All configuration, management, and reporting functions are exposed through a centralized, multi-tenant web Console, which consolidates data from all deployed Sensors and provides a single operational control point.
Andrisoft Wansight supports the sFlow standards. To learn more about sFlow please visit http://www.sflow.org.
| Wansight | Wanguard | |
|---|---|---|
| Flow & Packet Sensors, per-IP graphs, tops, accounting | yes | yes |
| Flow Collector & Packet Tracer forensics | yes | yes |
| 95th-percentile billing, scheduled reports | yes | yes |
| Multi-tenant Console, SAML / LDAP / RADIUS, API | yes | yes |
| DDoS anomaly detection, 150+ metrics | — | yes |
| Automatic responses: Flowspec, RTBH, diversion, scripts | — | yes |
| On-premise scrubbing with the Filter | — | yes |
| Standard license per Sensor, per year | $345 | $595 |
Volume discounts apply to the standard prices. Upgrading is a license-key swap on the same installation — no reinstall, nothing re-learned. Wansight licenses → · Wanguard pricing →
Supports all major traffic monitoring technologies: NetFlow, sFlow, IPFIX, 40/100 Gbps packet sniffing, DPDK, Netmap, PF_RING, and SNMP.
Provides consolidated management through an interactive, multi-tenant web portal with custom dashboards and user roles.
Produces advanced analytical reports with aggregated metrics across hosts, subnets, IP groups, ASNs, protocols, countries, interfaces, and more.
The software is engineered to run on low-cost commodity hardware, and all components can be clustered and distributed across multiple servers.
Integrates a comprehensive NetFlow, sFlow, and IPFIX data collector with powerful storage, searching, filtering, sorting, and export options.
Integrates a packet sniffer capable of collecting packet dumps from across the network, accessible online or available for download.
Bandwidth graphs are animated and offer short-term accuracy down to 5 seconds. Live readings are available for all parameters.
View reports covering any time range from the last 5 seconds to the last 10 years, and supports 95th percentile billing.
Any report can be generated and automatically emailed to designated recipients at scheduled intervals: hourly, daily, weekly, or monthly.
You can fine-tune every aspect of the system in great detail, including the user profiles, remote authentication, data retention, and much more.
All support inquiries are handled by skilled engineers. Enterprise Support guarantees a response time of under one hour, 24/7/365.
Provides a highly cost-efficient traffic monitoring platform, with annual subscriptions covering support and software upgrades.
Wansight uses the same Console and the same Sensors as Wanguard; only the detection, the responses and the Filter are Wanguard-only. Every component is a Linux package on your own servers.
Multi-tenant, with 40+ dashboard widgets, scoped views for customers, white-label login for MSSPs, PDF and Excel exports, 10 themes including a dark mode.
NetFlow v5/v7/v9, jFlow, cflowd, NetStream, sFlow v4/v5 and IPFIX; one instance per exporter, tens of instances per server; an optional flow collector with interactive flow graphs.
libpcap, PF_RING, Netmap or DPDK; 100 GbE and more than 30 Mpps per instance, clustered across CPU cores and servers; packet captures viewable in a Wireshark-like page.
Every feature, any number of servers, 30 days — by requesting a free evaluation license. Our engineers help you set it up.
Fill in the trial form. We review it and email download links, documentation and a 30-day license within 24 hours.
Any 64-bit Intel/AMD box or VM. Packages install under /opt in minutes; size the hardware with the system requirements.
Ask us anything during the trial. When it earns its keep, buy licenses in the online store — the trial installation carries on with the new key.
Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.