Wansight · traffic monitoring & accounting

Traffic monitoring for NetFlow, sFlow, IPFIX and mirrored ports.

Wansight is the visibility half of Wanguard: the same Flow and Packet Sensors, the same multi-tenant Console, without DDoS detection and mitigation. Deep traffic inspection, flow- and packet-level accounting and high-resolution bandwidth monitoring for NOC and IT operations teams — and when you need the protection later, a Wanguard license key upgrades the same installation, no reinstall.

$345 / year per Sensor · Console free · upgrades to Wanguard with a key

Routers export flows and mirror ports copy packets to the Wansight Sensors; the Console turns them into graphs, reports and billing WHAT IT LISTENS TO Your routersNetFlow · sFlow · IPFIXMirror port · TAPpackets at wire speedIn-line serversbridge or router Wansight Flow & Packet Sensors deep traffic inspection flow & packet accounting bandwidth graphs every 5 s forensics on demand Console graphs · tops · reports multi-tenant · 95th pct Your teamsNOC · IT operationscustomers · billing every 5 s no detection, no mitigation — visibility only a Wanguard key adds both later, on the same installation $345 / year per Sensor — the Console is free
  1. The same Sensors as Wanguard.Flow Sensors for NetFlow, sFlow, jFlow, NetStream and IPFIX; Packet Sensors for mirror ports, TAPs and in-line links.
  2. Visibility, not protection.Deep traffic inspection, flow- and packet-level accounting, high-resolution bandwidth monitoring — no anomaly detection, no mitigation.
  3. One Console for every team.Graphs, tops, reports and 95th-percentile billing; multi-tenant, with scheduled email delivery.
  4. Upgrades in place.A Wanguard license key turns the same installation into DDoS detection and mitigation — no reinstall.
flows and packets ingraphs, reports and billing out

See it, measure it, hand it to the right team

Collected telemetry is aggregated into detailed reports, time-series graphs and top lists — traffic distribution, protocol usage, host behavior, application performance — for capacity planning and the fast diagnosis of network problems.

See every host and application

Per-IP, per-subnet and per-IP-group graphs for 50+ traffic decoders, from TCP flags to QUIC, DNS, NTP and the streaming platforms; tops for talkers, external IPs, autonomous systems, countries, ports and protocols; accounting you can bill from, with 95th-percentile values.

Reports in the Wansight guide →

Analyze down to the packet

Reports from the last five seconds to the last ten years; the Flow Collector stores, searches, filters and exports flows — with Sankey, heatmap and stacked flow graphs from ClickHouse — and the Packet Tracer captures dumps you read in a Wireshark-like page, hex and ASCII included.

Flows and packets in the guide →

Share it, scoped

The multi-tenant Console gives NOC, IT operations, customers and departments their own dashboards and their own slice of the traffic — SAML, LDAP and RADIUS for sign-in, white-label branding, and any report emailed on a schedule as PDF or Excel.

The Console in detail →

Need DDoS detection and automatic mitigation? That is Wanguard — same Sensors, same Console, plus the anomaly engine, the responses and the Filter.

Wansight in detail — and next to Wanguard

What the traffic monitoring and analysis tool reads — flows and port-mirrored packets — and where Wanguard goes further.

Andrisoft Wansight is an enterprise-grade Linux-based monitoring platform that provides NOC / IT operations teams with a unified environment for comprehensive network visibility. Unlike Wanguard, it does not incorporate DDoS detection and mitigation capabilities.

Wansight utilizes the Flow Sensor and Packet Sensor modules to perform deep traffic inspection, flow and packet-level accounting, and high-resolution bandwidth monitoring. The Flow Sensor processes NetFlow, IPFIX, and sFlow data, while the Packet Sensor captures traffic from in-line interfaces, TAPs, and port-mirroring configurations at wire speed. Collected telemetry is aggregated and processed to generate detailed reports, time-series graphs, and top lists, enabling accurate analysis of traffic distribution, protocol usage, host behavior, and application performance. This information supports data-driven capacity planning and facilitates rapid diagnosis of network performance issues.

All configuration, management, and reporting functions are exposed through a centralized, multi-tenant web Console, which consolidates data from all deployed Sensors and provides a single operational control point.

Andrisoft Wansight supports the sFlow standards. To learn more about sFlow please visit http://www.sflow.org.

WansightWanguard
Flow & Packet Sensors, per-IP graphs, tops, accountingyesyes
Flow Collector & Packet Tracer forensicsyesyes
95th-percentile billing, scheduled reportsyesyes
Multi-tenant Console, SAML / LDAP / RADIUS, APIyesyes
DDoS anomaly detection, 150+ metricsyes
Automatic responses: Flowspec, RTBH, diversion, scriptsyes
On-premise scrubbing with the Filteryes
Standard license per Sensor, per year$345$595

Volume discounts apply to the standard prices. Upgrading is a license-key swap on the same installation — no reinstall, nothing re-learned. Wansight licenses →  ·  Wanguard pricing →

Key features and benefits

Full Network Visibility

Supports all major traffic monitoring technologies: NetFlow, sFlow, IPFIX, 40/100 Gbps packet sniffing, DPDK, Netmap, PF_RING, and SNMP.

Advanced Web Console

Provides consolidated management through an interactive, multi-tenant web portal with custom dashboards and user roles.

Complex Analytics

Produces advanced analytical reports with aggregated metrics across hosts, subnets, IP groups, ASNs, protocols, countries, interfaces, and more.

Fast & Completely Scalable

The software is engineered to run on low-cost commodity hardware, and all components can be clustered and distributed across multiple servers.

Flow Analyzer and Collector

Integrates a comprehensive NetFlow, sFlow, and IPFIX data collector with powerful storage, searching, filtering, sorting, and export options.

Distributed Packet Sniffer

Integrates a packet sniffer capable of collecting packet dumps from across the network, accessible online or available for download.

Real-Time Reporting

Bandwidth graphs are animated and offer short-term accuracy down to 5 seconds. Live readings are available for all parameters.

Historical Reporting

View reports covering any time range from the last 5 seconds to the last 10 years, and supports 95th percentile billing.

Scheduled Reporting

Any report can be generated and automatically emailed to designated recipients at scheduled intervals: hourly, daily, weekly, or monthly.

Flexible Configuration

You can fine-tune every aspect of the system in great detail, including the user profiles, remote authentication, data retention, and much more.

Outstanding Support

All support inquiries are handled by skilled engineers. Enterprise Support guarantees a response time of under one hour, 24/7/365.

Affordable Traffic Monitoring

Provides a highly cost-efficient traffic monitoring platform, with annual subscriptions covering support and software upgrades.

The components it runs on

Wansight uses the same Console and the same Sensors as Wanguard; only the detection, the responses and the Filter are Wanguard-only. Every component is a Linux package on your own servers.

Console

The workbench

Web UI, reports, dashboards, users and the API — the brain of the deployment.

Multi-tenant, with 40+ dashboard widgets, scoped views for customers, white-label login for MSSPs, PDF and Excel exports, 10 themes including a dark mode.

License
free, unlimited users
Auth
SAML 2.0, LDAP/AD, RADIUS
Automation
REST API, CLI, scripts
Console in detail →
Flow Sensor

Listens to routers

Collects and analyzes the flows your routers already export.

NetFlow v5/v7/v9, jFlow, cflowd, NetStream, sFlow v4/v5 and IPFIX; one instance per exporter, tens of instances per server; an optional flow collector with interactive flow graphs.

Per instance
1 exporter, tens of 10/40/100 GbE ports
Detection
≤ export time + 5 s
License
$595 / year
Flow Sensor in detail →
Packet Sensor

Sniffs the wire

Inspects packets from a mirror port, a TAP or an in-line link.

libpcap, PF_RING, Netmap or DPDK; 100 GbE and more than 30 Mpps per instance, clustered across CPU cores and servers; packet captures viewable in a Wireshark-like page.

Per instance
100 GbE, > 30 Mpps
Detection
≤ 1 s
License
$595 / year
Packet Sensor in detail →

Wanguard overview →  ·  Flow Sensor →  ·  Packet Sensor →

Try the full product on your own hardware

Every feature, any number of servers, 30 days — by requesting a free evaluation license. Our engineers help you set it up.

Request a trial key
Debian 11–13Ubuntu 20–26RHEL 9–10RockyAlmaLinux
1

Request a key

Fill in the trial form. We review it and email download links, documentation and a 30-day license within 24 hours.

2

Install on a spare Linux server

Any 64-bit Intel/AMD box or VM. Packages install under /opt in minutes; size the hardware with the system requirements.

3

Run it for real, then buy

Ask us anything during the trial. When it earns its keep, buy licenses in the online store — the trial installation carries on with the new key.

Already running Wanguard?

Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.