Traffic Analysis & Protocol Breakdown
RoutePulse delivers multi-dimensional traffic analysis spanning source and destination AS, IP addresses, protocols, applications, countries, and time windows. Deep Packet Inspection classifies 1,575 applications across 16 categories using 272 port-based rules, achieving a 92% classification rate. All flow data is stored in a ClickHouse columnar analytics engine with 14 materialized views for instant aggregation, 9.5x ZSTD compression, and a full 180-day retention window. Eight KPI cards present total bytes and packets in and out, peak bandwidth, active protocols, and top applications at a glance. A traffic timeline renders area charts with per-source stacked views separating transit from IXP peering traffic, while top ASNs by volume, top destination and source IPs, and port distribution tables provide the detailed breakdowns operators need.
A GeoIP traffic heatmap leverages city-level MaxMind resolution with country breakdown tables to show exactly where traffic originates and terminates. The protocol hierarchy view provides IPv4/IPv6 split analysis, TCP/UDP/ICMP breakdowns, and per-protocol byte and packet counts. Transit versus peering analysis shows traffic distribution across upstream providers including Colt, Cogent, Antenna, and Lumen, as well as IXP presences at SwissIX, MIX-IT, and MINAP. Multi-protocol flow collection ingests sFlow v5, IPFIX, and NetFlow v9 from 5 active sources. A dual Longest Prefix Match enrichment pipeline achieves a 98.8% ASN enrichment rate using a 3-tier approach: RIB cache for the fastest path, direct RIB lookup as fallback, and WhoisService as the final tier.
Key Capabilities
- Multi-dimensional traffic analysis across source/destination AS, IP, protocol, application, country, and time
- Deep Packet Inspection classifying 1,575 applications across 16 categories with 272 port-based rules at 92% accuracy
- ClickHouse columnar engine with 14 materialized views, 9.5x ZSTD compression, and 180-day retention
- 8 KPI cards displaying total bytes/packets in/out, peak bandwidth, active protocols, and top applications
- Traffic timeline with area charts and per-source stacked views separating transit from IXP peering
- GeoIP traffic heatmap with city-level MaxMind resolution and country breakdown tables
- Protocol hierarchy view: IPv4/IPv6 split, TCP/UDP/ICMP breakdown, per-protocol byte and packet counts
- Transit vs. peering analysis across providers (Colt, Cogent, Antenna, Lumen) and IXPs (SwissIX, MIX-IT, MINAP)
- Multi-protocol flow collection: sFlow v5, IPFIX, and NetFlow v9 from 5 active sources
- Dual LPM enrichment pipeline achieving 98.8% ASN enrichment via 3-tier lookup: RIB cache, direct RIB, WhoisService
- Top ASNs by traffic volume, top destination/source IPs, and port distribution analysis
Engineered and operated by the GOLINE SOC & Network Engineering team.
Explore all RoutePulse features →