Flow Sensor is the component of Wanguard and Wansight that listens to what your routers already export — NetFlow v5/v7/v9, jFlow, cflowd, NetStream, sFlow v4/v5, IPFIX — and turns it into per-IP graphs for hundreds of thousands of addresses, tops, accounting and stored flows. With a Wanguard license it also detects the attack, within the export interval plus a second or two.
Wanguard overviewFlows or packets?Sensor licenses
1 exporter per instance · tens per server · detects in ≤ export time + 5 s
A scalable traffic-correlation engine monitors hundreds of thousands of IPv4 and IPv6 addresses and ranges in real time and hands everything to the Console; nothing changes in your data path.
Traffic accounting and per-IP, per-subnet or per-IP-group graphs for 50+ decoders — IP, TCP flags, UDP, ICMP, QUIC, DNS, NTP, SNMP, SSDP, memcached, GRE, IPv4/IPv6, YouTube, Netflix and yours. Tops and graphs for talkers, external IPs, IP groups, autonomous systems, transit ASes (from BGP MRT files), countries, ports and protocols. Bandwidth histograms with 95th-percentile values.
IP reports in the docs →With a Wanguard license: DDoS and unknown volumetric DoS; NTP amplification, UDP, ICMP and SMURF floods; SYN floods, TCP/UDP port 0, LOIC, peer-to-peer attacks; scans and worms hitting illegal or unallocated addresses; traffic missing from critical services. Anomalies are checked as often as every second — detection in the flow export time plus a second or two.
How detection works →Activate on-premise mitigation with Wanguard Filter — a Flow Filter derives its rules straight from this Sensor's flows, on minimal hardware; announce RTBH blackholes with Flowspec (RFC 5575) or null-routing communities; send BGP off-/on-ramp diversion to an on-premise or cloud scrubber; email alerts from dynamic templates; syslog to your SIEM; or run your scripts through an API exposing 130+ parameters.
Response actions in the docs →Flows or packets? A Flow Sensor needs no extra hardware and tens of them share a server; a Packet Sensor sees every packet, with detection in one second and five-second graphs. Many networks run both — choosing a method of traffic monitoring.
Switch on the Flow Collector and every received flow is stored on the Sensor's disk in a compressed binary format — for forensics, situational awareness and troubleshooting. Store them in ClickHouse as well and the Console turns them into interactive Flow Graphs.
Flows are searched, filtered, sorted and exported from the Console's Flow Collector page; the Console's graph storage and data retention are configured per Sensor.
Many entry-level and most enterprise routers and switches export IP traffic information as flow records in one of these formats — the Flow Sensor needs nothing else.
| Datasheet | Flow Sensor | Notes |
|---|---|---|
| Flow technology | Cisco NetFlow v5, v7, v9 · jFlow · cflowd (Juniper, Alcatel) · NetStream (Huawei) · FlowMon · sFlow v4, v5 · IPFIX | one flow exporter per instance |
| Capacity per instance | 1 exporter with tens of 1 / 10 / 40 / 100 GbE interfaces | no limit on interfaces or flows per second |
| DDoS detection time | ≤ flow export time + 5 seconds | anomalies checked as often as every second |
| Graphing accuracy | ≥ 60 seconds per IP; 5 s – 1 min short-term, any number of years long-term | set per Sensor |
| Traffic validation | IP classes, interfaces, AS numbers, ingress / egress | — |
| Minimum server | per Flow Sensor server | Notes |
|---|---|---|
| Architecture | 64-bit x86; a dedicated server for production | virtual machines (VMs) are fine for the trial, not recommended in production |
| CPU · RAM | 2.0 GHz dual-core Xeon · 8 GB | a server with enough RAM runs tens of Flow Sensors |
| Network cards · disk space | 1 × Gigabit Ethernet · 60 GB including the OS | plus local storage when the Flow Collector is on |
| Operating system | RHEL / Rocky / AlmaLinux 9–10 · Debian 11–13 · Ubuntu Server 20–26 | other distributions may work, untested |
Full system requirements →Configuring NetFlow export →Sensor licenses, $595 / year →
NetFlow, sFlow & IPFIX Analyzer and Collector for Wanguard and Wansight
The Flow Sensor component of Wanguard and Wansight is a fully-featured flow-based traffic analyzer and collector that supports NetFlow version 5, 7 and v9; sFlow version 4 and 5; and IPFIX. At its core, Flow Sensor contains a highly scalable traffic correlation engine capable of continuously monitoring hundreds of thousands of IP addresses in real-time. Sophisticated statistical algorithms integrate traffic data to build an accurate and detailed picture of real-time and historical traffic flows across the network.
Flow Sensor is one of four components; every one reports to the same Console. Wansight runs the same Sensor without detection and mitigation — and becomes Wanguard with a license key.
Multi-tenant, with 40+ dashboard widgets, scoped views for customers, white-label login for MSSPs, PDF and Excel exports, 10 themes including a dark mode.
libpcap, PF_RING, Netmap or DPDK; 100 GbE and more than 30 Mpps per instance, clustered across CPU cores and servers; packet captures viewable in a Wireshark-like page.
Packet Filter inspects diverted or in-line packets, with deep packet inspection for payload patterns; Flow Filter derives the same rules from any Flow Sensor's flows on minimal hardware. Both apply them anywhere: local Netfilter, in-NIC filters (Intel 82599, Chelsio T5+, any DPDK Flow API card), BGP Flowspec routers or third-party appliances.
Every feature, any number of servers, 30 days — by requesting a free evaluation license. Our engineers help you set it up.
Fill in the trial form. We review it and email download links, documentation and a 30-day license within 24 hours.
Any 64-bit Intel/AMD box or VM. Packages install under /opt in minutes; size the hardware with the system requirements.
Ask us anything during the trial. When it earns its keep, buy licenses in the online store — the trial installation carries on with the new key.
Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.