pktvisor is a dynamic network observability agent that analyzes at the edge
10K+
Please see https://pktvisor.dev or https://github.com/ns1labs/pktvisor for instructions.
pktvisor (pronounced "packet visor") is an observability agent for analyzing high volume, information dense network data streams and extracting actionable insights directly from the edge while integrating tightly with modern observability stacks.
It is resource efficient and built from the ground up to be modular and dynamically controlled in real time via API and YAML policies. Input and analyzer modules may be dynamically loaded at runtime. Metric output can be used and visualized both on-node via command line UI (for localized, hyper real-time actions) as well as centrally collected into industry standard observability stacks like Prometheus and Grafana.
The input stream system is designed to tap into data streams. It currently supports packet capture, dnstap and sFlow and will soon support additional taps such as Netflow, envoy taps, and eBPF.
The stream analyzer system includes full application layer analysis, and efficiently summarizes to:
Counters Histograms and Quantiles Timers and Rates Heavy Hitters/Frequent Items/Top N Set Cardinality GeoIP/ASN Please see the list of current metrics or the sample metric output.
pktvisor has its origins in observability of critical internet infrastructure in support of DDoS protection, traffic engineering, and ongoing operations.
Content type
Image
Digest
sha256:4f6c69f0e…
Size
100.8 MB
Last updated
over 3 years ago
docker pull ns1labs/pktvisor