traffic66
traffic66 blogNetFlow / sFlow / IPFIXOctober 2026

We installed the flow analyzers on GitHub, one after another

This post measures one thing: how far a network admin has to go from download to a first chart whose numbers they trust. traffic66 has the shortest path. On security detection it is level with ntopng. On scale, deep packet inspection and community, others are ahead. Every claim is checked against the other projects' own documentation, with links at the end.

The field

We took the projects on GitHub for sFlow, NetFlow and IPFIX with the most stars. Some are complete products, some are only collectors, some are archived. Star counts are those shown on GitHub.

ProjectStarsWhat it isWhat you install firstStatus · licence
ntopng8.1kWeb traffic monitor with nDPI deep packet inspectionRedis; for NetFlow/sFlow, nProbe, which needs a licenceactive GPL-3.0
FastNetMon3.7kDDoS detection, can trigger BGP blackholingLinux; charts through InfluxDB/Grafana or similaractive GPL-2.0
ElastiFlow (legacy)2.5kLogstash pipeline and Kibana dashboardsElasticsearch, Logstash, Kibanaarchived 2024-03
Akvorado2.3kCollector, enricher and visualizerinlet, Kafka, outlet, ClickHouse; Redis in the official composeactive AGPL-3.0
pmacct1.2kCollector daemons with BGP and BMPA database and dashboards of your choice (often Grafana)active GPL (moving to BSD-style)
vflow1.2kCollector feeding KafkaKafka plus storage and dashboards downstreamApache-2.0
nfdump922Command-line collection and query toolsNo web UI of its ownactive BSD
Cloudflare goflow919The collector Cloudflare used internallyKafka plus downstreamarchived 2025-02
GoFlow2798High-performance collectorOutput to Kafka or files; storage and UI are yours to buildactive BSD-3
traffic66newCollector, storage, web and terminal UI, detection, pcap analysisNothing: one executable with embedded DuckDBactive source-available (see below)

The current ElastiFlow is now called NetObserv Flow. It is closed source; its free Community tier is limited to 500 flow records per second.

1. From download to the first chart

This is the part we care about most. When someone asks at 3 p.m. who is filling the uplink, nobody wants to learn Kafka first. These are the shortest paths in each project's documentation:

traffic66
download, unpack./traffic66open the browser ✓
ntopng
add the repositoryinstall ntopnginstall Redisinstall nProbeget an nProbe licenceconnect the twochart
Akvorado
install Dockerfetch the composestart Kafkastart ClickHousestart inlet/outletset up SNMP, GeoIPchart
ElastiFlow
install Elasticsearchinstall Kibanainstall the collectorimport dashboardsmind the 500 rec/s capchart
GoFlow2 / pmacct
install the collectorchoose a databasebuild the pipelineinstall Grafanadraw your dashboardschart

A new traffic66 installation signs in as admin / traffic66 and asks for a password of your own at the first sign-in. On Windows, double-clicking traffic66.exe opens the browser. To look around first, traffic66 demo builds a simulated company network with a day of history and a complete attack.

About Windows: almost everything in the table runs on Linux or Docker only. traffic66 builds native Windows, Linux and macOS programs from the same code, with no WSL and no Docker. In many small organizations the monitoring machine is a Windows PC.

3 steps
from download to the first chart

2. Do the numbers match the interface counters?

The question every flow tool gets: the chart says the uplink carries 800 Mb/s, SNMP in Zabbix says 600. Which one is right?

Flow numbers are estimates: sampled packets times the sampling rate. traffic66 has a page for exactly this, Interface check. It draws each interface's flow estimate and the device's own counters (sFlow counters or SNMP) in one chart, and computes the difference and the statistical error of sampling. When the difference is larger than sampling explains, it names the likely cause: interfaces not sampled, the same traffic sampled on two interfaces, export packets lost on the way, or a sampling rate not yet received.

Behind it are a few quiet details: the sampling rate the device actually applied; records held until their sampling rate arrives instead of being counted 1:1; compensation for lost export packets; long flows spread over the minutes they lasted; and Ethernet overhead added to NetFlow byte counts, because interface counters include it.

Interface check: bits per second and packets per second, the list of interfaces, and the verdict
Interface check. Dashed lines are the device counters; the verdict is at the lower right.

How far the others go:

traffic66Flow estimate and device counters in one chart, difference and statistical error computed, the cause stated. sFlow counters are used as they arrive; for a NetFlow device, one snmp line.
ntopngThe Enterprise edition polls SNMP and charts device interfaces; the documentation does not mention comparing them with flows. SNMP in the Community edition is not documented.
AkvoradoUses SNMP for interface names and descriptions on flow records, not counters.
ElastiFlowAlso uses SNMP to enrich interface details; a comparison means building two Kibana charts yourself.
FastNetMonNot its job; it watches attack thresholds.
GoFlow2 and othersNot their job; they deliver flow records.

Elsewhere, interface counters are either not read or shown as one more chart to compare by eye. We did not find another project that states why the numbers differ.

3. A conclusion on opening, no query language

The overview answers how much traffic there is now, who uses it, and how that compares with yesterday. Every address, port, application and country can be clicked: show only this, exclude it, open its flow records, open its details page. The interface is designed so that you rarely need to type.

Overview: interface bandwidth, bandwidth by application compared with yesterday
Overview. The interface is chosen at the top; the starred one is the default. The dashed line is the same time yesterday.

The same job in the other projects:

traffic66Web UI and terminal UI built in, opening on a summary. 13 languages.
ntopngA complete UI with a lot of information; the only one in the table to compare head-on. Seven languages per its announcements.
AkvoradoA polished web console; its visualizer lets you drag dimensions and draw Sankey charts. It works more like a query tool: you decide what to ask first. English only.
ElastiFlowKibana dashboards; changing them means learning Kibana.
FastNetMonNo web UI in the Community edition; charts through Grafana. The web UI is in the commercial edition.
GoFlow2, pmacct, vflow, nfdumpNo UI; nfdump has command-line queries. You build the dashboards, usually in Grafana, one query per chart.

4. Finding attacks in sampled data

Detection on sampled data is hard: at 1:4096, a scan may leave a handful of packets. traffic66's rules are calibrated for sampled data. In the demo, the whole attack chain is found through 1:4096 sFlow: internal scan, port scan, password guessing, lateral movement, a large upload to a new address, and threat list traffic. A day of the demo's normal traffic produces no other findings, apart from the internet scanner knocking on the website.

Findings: each step of an attack, most serious first
Findings. Every step of an attack by a compromised host in the demo, all from 1:4096 sFlow sampling.

Here the comparison is closer:

traffic66Scans, port scans, password guessing, lateral movement, unusual uploads, floods and threat lists, with thresholds for sampled data.
ntopngMany more checks than ours: scans, floods, blacklists, DNS and ICMP exfiltration, lateral movement, already in the Community edition. ntopng is ahead here.
FastNetMonDDoS only, but in depth: detection within seconds and automatic BGP blackholing.
ElastiFlowNetIntel threat enrichment; alerting through rules you set up in Elastic.
Akvorado and the collectorsNo security detection.

On security we are level with ntopng. What we offer is that the checks come in one program without setup, and are tuned for sampled data.

One more convenience: traffic66 capture.pcap analyses a packet capture with the same pages, kept apart from the live data. ntopng reads pcap files too, so call this one even.

Scorecard

The points above and the weaknesses below in one table. Filled means done, half means partly, paid or a separate install, empty means not there.

Capabilitytraffic66ntopngAkvoradoElastiFlow (current)FastNetMonCollectorsGoFlow2 · pmacct · vflow · nfdump
One program, ready after installRedis + nProbe licenceKafka + ClickHouseElasticsearch + KibanaGrafana for chartsbuild storage and UI
Runs natively on WindowsWindows build is a demo
Built-in web UIKibana dashboardscommercial edition
UI in many languages137EnglishKibana only
Flows checked against interface countersSNMP charts (Enterprise)build it yourself
Security detectionmost checksthreat enrichmentDDoS only, with mitigation
Offline pcap analysis
Terminal UIconsole clientnfdump CLI
Layer-7 application recognitionnDPI
Horizontal scale-out5,000 records/s, one machinepaid tiers
OSI open-source licencesource-availableclosed
done partly, paid or separate install not there

traffic66 fills the first eight rows; no other column does. The last three rows are our weak points.

Where others do better

Read this section before you choose.

Akvorado · GoFlow2

Scale

traffic66 is designed for 5,000 flow records per second on one machine with embedded DuckDB. For carrier-scale traffic, a Kafka and ClickHouse architecture that scales out is the right answer.

ntopng

Deep packet inspection

ntopng has nDPI and recognizes hundreds of layer-7 protocols. traffic66 works on flows; applications are known by port, packets are not parsed.

FastNetMon

Automatic DDoS mitigation

FastNetMon can announce a BGP blackhole or FlowSpec rule as soon as it detects an attack. traffic66 reports floods and leaves routing alone.

pmacct

Routing data and flexibility

pmacct takes BGP and BMP alongside flows, adds routing information to records and writes to almost anything. traffic66 is a finished product, not a toolkit.

The established projects

Age and community

ntopng has close to 30,000 commits; nfdump has been around for two decades. traffic66 has only started collecting stars and has far less production mileage.

Most of the table

Licence

They use OSI-approved open-source licences. traffic66 is source-available: free for evaluation and for organizations under 100 people; larger organizations register after 30 days. Nothing is switched off, but it is not open source.

Which one to pick

One machine, tens to hundreds of interfaces, charts this afternoon, numbers that match SNMPtraffic66
Layer-7 visibility, or mostly mirror portsntopng
A carrier or large backbone, hundreds of thousands of flows per secondAkvorado
DDoS detection with automatic blackholingFastNetMon
You already run Kafka and a data platform and need a collectorGoFlow2 / pmacct
Command line, long-term raw recordsnfdump

What we are confident about is three things: quick to install, easy to read, and numbers that match. For the rest, issues on GitHub are welcome; we will close the gaps one by one.