skip to content

Network Telemetry

Syslog messages, flow records, mirrored packets and streamed model-driven counters each show a different slice of a network. Interviewers ask which one you would reach for to find a given fault.

on this pageshow

explore

questions

23

In NetFlow and IPFIX flow export, what is a flow key, and how does an exporter turn packets into flow records?

level: juniorimportance: must knowfreq 35%

answer

  1. fields every packet in it shares
  2. one cache entry per key
  3. the five-tuple, one direction only
  4. key fields versus accumulated fields
  5. expire the entry, then export it

basics

~20 s

A flow key is the set of fields, classically the five-tuple, that packets must share to count as one flow. The exporter keeps a cache entry per key, adds each matching packet to it, and exports it as a record on expiry.

solid answer

~50 s

RFC 7011 calls a **flow key** each field used to define a flow: a header field such as the destination address, a property of the packet such as its length, or a value derived from treatment such as an AS number. The traditional key is the five-tuple (source and destination address, source and destination port, protocol), which groups one *direction* of one conversation, so a TCP connection normally becomes two flows. The metering process looks each packet's key up in a flow cache: a hit adds to that entry's packet and byte counters and moves its end time; a miss creates an entry. Fields outside the key are accumulated, such as NetFlow v9's `TCP_FLAGS`, the union of all flags seen. When the entry expires (idle, long-lived, TCP end, or cache pressure) the exporting process sends it to a collector as one record.

go deeper

for a junior

Recall the five-tuple, that a flow is one direction, and that a record carries counters and timestamps rather than packet contents.

for a middle

Walk through the cache lookup: key fields select the entry, counters accumulate, non-key fields such as TCP flags are folded in, and expiry triggers export.

for a senior

Show that the key is a design choice: every added field multiplies cache entries and export volume, and a coarse key loses the detail later questions need.

for a principal

Frame key choice as a cost decision across the estate: what the analysts must be able to answer versus what cache memory and collector capacity can carry.

## What a flow is **Flow export** is how a router or switch summarises the traffic it forwards without copying the packets. Three specifications describe the record formats a candidate meets: **NetFlow v5**, a fixed-format vendor export with no RFC at all; **NetFlow v9**, published as Informational RFC 3954; and **IPFIX**, the IETF standard in RFC 7011 (STD 77) with its information model in RFC 7012. All three share the same idea. RFC 7011 defines a **flow** as a set of packets passing an observation point during a time interval that share a set of common properties. Those common properties are the **flow keys**. Each flow key is a field that is: - part of the packet header, such as the destination IP address; - a property of the packet itself, such as its length; or - derived from how the device treated it, such as an Autonomous System number. The textbook example in RFC 7011 is the **five-tuple**: source and destination address, source and destination transport port, and transport protocol. It groups the packets of a single *direction* of communication on a single socket. Because a reply swaps source and destination, it carries a different key, so one TCP connection normally produces **two** flows. ## The key decides the granularity The key is a configuration choice, and it trades detail against cache size and export volume. | Key | One record covers | Effect | |---|---|---| | five-tuple | one direction of one socket pair | the common default, detailed | | five-tuple + DSCP or ingress interface | the same, split by marking or port | more entries, more records | | destination prefix only | everything sent to one prefix | far fewer entries, no per-host detail | Adding a field to the key can only split flows further: two packets that differ in that field now land in different entries. ## The flow cache, step by step The part of the exporter that builds flows is the **metering process**, and its working store is the **flow cache**. 1. A packet arrives (or is selected, if the exporter samples). 2. The metering process extracts the key fields and looks them up. 3. On a **hit**, it adds one to the entry's packet counter, adds the packet's length to its byte counter, updates the last-seen time and folds in non-key fields such as TCP flags. 4. On a **miss**, it creates an entry with the first-seen time. 5. When the entry **expires**, the exporting process encodes it as a **flow record** and sends it to a collector. RFC 3954 and RFC 5470 list the expiry reasons: the exporter detects the end of a flow (a TCP FIN or RST), the flow has been idle for the inactive timeout, a long-lived flow reaches the active timeout, or the device runs short of resources, such as cache memory. ## What a record carries A typical record holds: - the **key fields**, such as `sourceIPv4Address` and `destinationIPv4Address`; - **counters**, which IPFIX calls `packetDeltaCount` and `octetDeltaCount`; - **timestamps** for the first and last packet; - **accumulated non-key fields**, such as NetFlow v9's `TCP_FLAGS`, the cumulative flags seen in the flow, plus the input and output interfaces. A typical flow record carries no payload: it summarises header fields and counts rather than copying the packets. ## Formats and transport around the record | Format | Status | Record layout | |---|---|---| | NetFlow v5 | vendor documentation, no RFC | fixed fields, IPv4 only | | NetFlow v9 | RFC 3954, Informational | described by templates | | IPFIX | RFC 7011, Standards Track | described by templates, version number 10 | Records usually travel to the collector over **UDP**, which is cheap for the exporter but unreliable. IPFIX also defines SCTP and TCP and assigns port **4739** (4740 for secure transport). Because templates in v9 and IPFIX describe each record's fields, the key and the carried fields can change without a new protocol version. RFC 3954 notes that adding a field to the older fixed formats meant a new export version. ## Traps to avoid - Calling a flow a *connection*: with the five-tuple, a flow is one direction. - Treating every field as a key: counters and timestamps describe the flow and never split it. - Assuming one record per conversation. Timeouts split long flows into several records, which the next question in an interview usually probes.

  • In NetFlow or IPFIX, what happens to the record count if you add DSCP to a five-tuple flow key?
    It can only rise. Packets of the same socket pair that carry different DSCP values now land in separate cache entries, so a conversation whose marking changes mid-stream becomes several flows. The cache needs more entries and the collector receives more records. In return, a record can now report traffic by marking, which a five-tuple key would have merged.
  • Why is NetFlow v9's TCP_FLAGS field accumulated rather than used as part of the flow key?
    Flags change packet by packet within one connection: SYN, then ACK, then FIN. Keying on them would split one conversation into many flows. As a non-key field, RFC 3954 records the cumulative flags seen in the flow. A record that saw SYN but never ACK then tells you the handshake never completed, without splitting the flow.

saying these in an interview costs you the question

  • A flow record is a copy of the packets in the conversation.
  • One TCP connection always produces exactly one flow record.
  • The flow key must be the five-tuple; no other fields can be keys.
  • Every field in a flow record is part of the flow key.
  • The exporter normally sends a record for every packet it forwards.
open as a page

Why does streaming telemetry from network devices beat five-minute SNMP polling when you monitor 2,000 routers and switches?

level: juniorimportance: must knowfreq 40%

basics

~20 s

SNMP polling makes a manager ask every device for every value each cycle, so data arrives late, averaged and lost under stress. Streaming telemetry subscribes once; each device then pushes YANG-modelled values on a timer or on change.

open as a page

What are syslog's eight severity levels, and what does a filter for 'Warning and more urgent' actually select?

level: juniorimportance: must knowfreq 45%

basics

~10 s

Syslog severities run from 0 Emergency to 7 Debug, and a lower number means a more urgent message. 'Warning and more urgent' therefore selects 0 to 4: Emergency, Alert, Critical, Error and Warning.

open as a page

How do a NetFlow or IPFIX exporter's active and inactive timeouts decide when flow records are sent, and what do they do to per-minute graphs?

level: middleimportance: must knowfreq 25%

basics

~20 s

The inactive timeout expires a flow that has gone quiet; the active timeout exports a long-lived flow in slices. Collectors see traffic only when records arrive, so a long active timeout piles a long transfer into one graph spike.

open as a page

How does a network TAP differ from a SPAN port as a packet source, and what happens to the monitored link when each loses power?

level: middleimportance: must knowfreq 30%

basics

~20 s

A SPAN port is switch configuration copying frames best effort; a TAP sits in the cable and copies the signal. A passive optical TAP needs no power, so a power cut is harmless; an active copper TAP typically drops the link briefly.

open as a page

In a gNMI STREAM subscription, why sample interface counters but put oper-status on ON_CHANGE, and what do heartbeat_interval and suppress_redundant add?

level: middleimportance: must knowfreq 30%

basics

~20 s

Counters change with every packet, so a gNMI SAMPLE subscription sends them on a fixed sample_interval; status changes rarely, so ON_CHANGE sends it only when it moves. heartbeat_interval forces periodic re-sends so silence is distinguishable from a dead stream.

open as a page

A firewall's syslog message begins with <134>; how do you decode that PRI value into a facility and a severity?

level: middleimportance: must knowfreq 35%

basics

~20 s

PRI is facility times 8 plus severity, so divide by 8: the quotient is the facility, the remainder the severity. 134 = 16 x 8 + 6, which is facility 16 (local0) and severity 6 (Informational).

open as a page

An IDS team says its SPAN feed of a 10 Gb/s link misses packets, though the link averages only 4 Gb/s in and 3 Gb/s out; why?

level: seniorimportance: must knowfreq 27%

basics

~20 s

Both directions of the link converge on one 10 Gb/s destination port, so coinciding bursts offer up to 20 Gb/s. The egress buffer fills within milliseconds and the switch drops the surplus copies first, even though the averages total only 7 Gb/s.

open as a page

When syslog over UDP 514 bursts from a firewall pair to one collector during an incident, what is lost and how can you tell?

level: seniorimportance: must knowfreq 30%

basics

~20 s

Whole messages vanish and nothing tells the collector: RFC 5426 gives UDP syslog no acknowledgement, retransmission or congestion control. You can only see the loss if messages carry a sequence number, such as RFC 5424's meta sequenceId, or syslog-sign signature blocks.

open as a page

What does a port mirroring (SPAN) session on an Ethernet switch do, and why do you need one to capture other hosts' traffic?

level: juniorimportance: should knowfreq 38%

basics

~20 s

A SPAN session makes an Ethernet switch copy frames received, sent, or both on chosen source ports or VLANs to a destination port for a capture host. It is needed because a switch sends known unicast only out of the destination's port.

open as a page

How does sFlow's packet and counter sampling differ from a NetFlow or IPFIX exporter's flow cache, and what does each design cost?

level: middleimportance: should knowfreq 20%

basics

~20 s

An sFlow agent keeps no flow state: it sends a copy of the header of about 1 in N packets, plus periodic interface counters. A NetFlow or IPFIX exporter keeps a flow cache and exports aggregated records when entries expire.

open as a page

How do RSPAN and ERSPAN each carry a mirrored copy to a capture host on another switch, and what does each demand of the path?

level: middleimportance: should knowfreq 18%

basics

~20 s

RSPAN, a vendor feature, floods copies into a reserved VLAN that trunks carry to another switch, so it needs an unbroken layer-2 path. ERSPAN wraps each copy in GRE over IP, so it routes but needs MTU headroom and a trusted path.

open as a page

In gNMI Subscribe, how do the ONCE, POLL and STREAM subscription-list modes differ, and what does sync_response tell the collector in each?

level: middleimportance: should knowfreq 18%

basics

~20 s

In gNMI, ONCE sends all subscribed values, a sync_response and closes the RPC; POLL keeps the RPC open and answers each Poll message with values plus a sync_response; STREAM sends initial values, one sync_response, then updates indefinitely.

open as a page

What does an RFC 5424 syslog header carry that the older BSD format described in RFC 3164 lacks, and why does that matter?

level: middleimportance: should knowfreq 30%

basics

~20 s

RFC 5424 adds a VERSION, a timestamp with year, fractional seconds and UTC offset, separate APP-NAME, PROCID and MSGID fields, and STRUCTURED-DATA. RFC 3164 only recorded BSD practice: local time without year or zone, a hostname, then free text.

open as a page

What does moving syslog from UDP 514 to TLS on TCP 6514 fix, and what does it still not guarantee?

level: middleimportance: should knowfreq 25%

basics

~20 s

RFC 5425 adds TCP retransmission and congestion control, octet-counted framing, encryption, integrity and certificate authentication on each hop. It has no application acknowledgement, so a broken connection can lose messages unnoticed, and it does not prove who wrote a message across relays.

open as a page

With 1-in-1000 packet sampling in NetFlow, IPFIX or sFlow at a 100 Gb/s edge, how do you scale sampled counts up, and how far can you trust them?

level: seniorimportance: should knowfreq 14%

basics

~20 s

Multiply sampled packet and byte counts by N, the 1-in-N sampling rate. With random sampling, an estimate from c samples has a relative error near 1/sqrt(c): big aggregates are accurate to a fraction of a percent, small flows are mostly noise.

open as a page

Why does an IPFIX collector that just restarted fail to decode UDP exports for minutes, and what in the protocol bounds that gap?

level: seniorimportance: should knowfreq 12%

basics

~20 s

IPFIX and NetFlow v9 data records can only be parsed with the template they reference, and a restarted collector has lost its templates. Over UDP the exporter cannot tell, so decoding resumes at its next periodic template retransmission.

open as a page

A switch port's CRC error counter keeps rising, yet a SPAN capture of that port shows no damaged frames; why, and how would you see them?

level: seniorimportance: should knowfreq 12%

basics

~20 s

The receiving port checks each frame's FCS and discards a damaged frame before the forwarding pipeline, where mirror copies are made, so a SPAN copy typically never includes it. A passive TAP plus a capture interface that keeps bad frames shows them.

open as a page

For streaming telemetry from 2,000 devices, when should collectors dial in with gNMI Subscribe, and when should devices dial out using RFC 8639 configured subscriptions?

level: seniorimportance: should knowfreq 15%

basics

~20 s

Dial in when the collector can reach every device and should own the subscriptions. Dial out when devices sit behind NAT or firewalls, or subscriptions must survive reboots: RFC 8639 configured subscriptions live in device configuration and connect to receivers themselves.

open as a page

How does a YANG-Push on-change subscription keep a collector's copy of interface state in sync, and how does the receiver notice a lost update?

level: seniorimportance: should knowfreq 10%

basics

~20 s

A YANG-Push on-change subscription starts with a full push-update when sync-on-start is true, then sends push-change-update YANG Patch deltas. A receiver detects loss through gaps in a counting patch-id or an incomplete-update flag, then resynchronises.

open as a page

When firewall syslog reaches a collector through a relay and events look out of order, which timestamps and fields can you trust?

level: seniorimportance: should knowfreq 22%

basics

~20 s

Trust an RFC 5424 TIMESTAMP only as far as the originator's clock was synchronised, which timeQuality can state. BSD timestamps lack year and zone and may be a relay's own time. Arrival order and the datagram's source address prove neither sequence nor origin.

open as a page

How does gNMI encode a path such as /interfaces/interface[name=eth0]/state/counters, and what do prefixes, keys and wildcards do in a subscription?

level: middleimportance: nice to knowfreq 8%

basics

~20 s

gNMI encodes a path as a list of PathElem messages: a node name plus an optional map of list keys, sent as strings. A prefix is prepended to each path; omitted keys, * and ... are wildcards, and subscriptions include descendants.

open as a page

A SPAN session mirrors both directions of two ports on one switch, and every packet between their hosts appears twice; why, and what does broker deduplication cost?

level: seniorimportance: nice to knowfreq 9%

basics

~20 s

Each packet enters on one mirrored port and leaves by the other, and both passes are copied. Receive-only mirroring on both ports copies each once; broker deduplication needs a window and a field list, and can discard genuine packets.

open as a page