In Part 7, I got the routers and switches into Grafana, the dashboard I use to view the lab’s monitoring data. I could check interface traffic, errors and discards, and see the state of the routing sessions. That gave me a place to start when something went wrong.
The next thing I wanted was context for those graphs. If traffic between the datacenters increased, which hosts were responsible? What were they talking to?
Looking at network state raised another set of questions. BGP is the routing protocol these devices use to exchange reachability information. Seeing an established session tells me two devices are communicating, but I might still need to know whether a destination is in the routing table and where the device will send its packets next. I wanted to search that information across the Cisco routers and Arista switches without opening a console on each one.
Those questions led me to NetFlow, sFlow and SuzieQ. NetFlow summarizes the traffic a router observes. sFlow exports samples of traffic passing through a device. SuzieQ collects operational information from the devices and makes it available through a common query interface.
I already had an OpenTelemetry Collector receiving SNMP measurements. The Collector is a service that receives telemetry, processes it and sends it to storage. Adding flow collection would give me traffic details alongside the interface measurements. SuzieQ would give me a place to inspect routes, neighbors and interfaces across both platforms.
I’ll follow a file transfer between two datacenters, find its traffic in the collected data, and use Nautobot to put names beside the IP addresses. You don’t need prior experience with these tools to follow the example. Running it yourself assumes the earlier lab setup: devices, Nautobot inventory and the Kubernetes monitoring stack. The configurations below are from that lab, not a fresh-install guide.




