NSX Flow monitoring is a feature that allows detailed traffic monitoring to and from protected virtual machines. Flow monitoring can uniquely identify different machines and different services that are exchanging data and when enabled can identify which machines are exchanging data over specific applications. Flow monitoring also allows live monitoring of TCP and UDP connections and can be used as an effective forensic tool.
Flow monitoring data can be polled to a set interval and then analyzed. The default period is 24 hours and the minimum is one hour while the maximum data collection interval is two weeks. Keep an eye on the disk space being consumed by NSX Manager as the polling interval is set.
To view the flow monitoring data, follow these steps:
- Log in to your vCenter...