Flow Policy in ObserveOps

Overview
The flow policy functionality in ObserveOps empowers you to monitor and analyze network traffic flow data, such as NetFlow or sFlow, and generate alerts based on defined conditions. By leveraging flow policies, you can gain valuable insights into network performance, detect anomalies, and take appropriate actions to optimize your network.
Use-Case
Network Performance Monitoring: Set up flow policies to trigger alerts on network traffic metrics such as bandwidth utilization, packet loss, or latency. This helps you identify and resolve performance issues, ensuring optimal network operation.
Security Incident Detection: Configure flow policies to detect and alert on suspicious network traffic patterns, potentially indicating network-based attacks, malware infections, or unauthorized access attempts.
Capacity Planning: Utilize flow policies to monitor network traffic trends and patterns, allowing you to make informed decisions regarding network capacity upgrades, bandwidth allocation, or traffic shaping.
Application Dependency Mapping: Use flow policies to analyze communication flows between applications and services, facilitating the understanding of dependencies and improving troubleshooting and optimization processes.
By effectively utilizing flow policies in ObserveOps, you can proactively monitor and manage both log data and network traffic, ensuring the stability, security, and optimal performance of your IT infrastructure. Remember to tailor the instructions and details to match the specific features and options available in your ObserveOps product.
Default Flow Alert Policies
ObserveOps simplifies flow network monitoring with Default Flow Alert Policies, offering users a predefined set of alerts designed to proactively notify specific issues related to their flow network. These default flow alerts, including High BPS for TCP and UDP, ICMP Flood Attack, Malicious Activity with Black IP (Threat Feed Integration), and Very Low or No Flow, aim to promptly alert users to potential network issues.
Out-of-the-Box Flow Security Policies
ObserveOps ships with a preloaded pack of out-of-the-box Flow security policies that cover common network threats and abnormal traffic patterns. These policies are provisioned automatically on a fresh installation as well as on upgrades and are available under the Flow Policy module immediately, so administrators do not need to configure them manually before monitoring can start.
The OOB security policies target scenarios such as:
- Volumetric flood attacks (TCP, UDP, ICMP).
- Suspicious protocol behaviour and unexpected port usage.
- Traffic to or from blacklisted or malicious IPs.
- Data exfiltration signals such as unusual outbound bandwidth spikes.
- Zero-flow or low-flow anomalies that may indicate an outage or a stealthy tap.
Each OOB policy can be enabled, disabled, cloned, or edited from the Flow Policy list, the same way as user-created policies. This lets teams start with a security baseline out of the box and tune thresholds or notification targets to match their environment.
Create Flow Policy
Navigation
Go to Menu, Select Settings . After that, Go to Policy Settings
. Select Metric/Log/Flow policy. The list of the created policies is now displayed.
Click on to start creating a policy. From the panel on the left side of the screen, click on the Flow tab to start creating a metric policy. The screen to create a Flow Policy is now displayed.
From the policy list, you can Edit, Delete, or Clone any Flow policy. Clone copies the source policy's configuration into a new policy so you can adjust a few fields instead of building the policy from scratch. See Policy List Actions for details.
Enter the details of the following parameters to create a Flow Policy:
| Field | Description |
|---|---|
| Policy Name | Enter a unique name of the policy you want to create. |
| Tag | Enter a name to logically categorize the policy. You can quickly and easily identify a policy based on the tag assigned to it. |
Set Conditions
| Field | Description |
|---|---|
| Counter | Choose the specific counter you wish to create a policy for by selecting from the available options in the dropdown menu. This counter will be the basis for monitoring and generating alerts. |
| Aggregation | Determine the aggregation function that best suits your monitoring needs for the selected counter. This function allows you to consolidate and analyze the metric data over a defined period. |
| Operator | Select the operator that will be applied to the aggregated counter values to define the triggering condition for the alert. You can read more on global operators to understand each operator type. |
| Start Value & End Value | Specify the threshold values against which the aggregated counter values will be compared. Once the counter value meets the specified range, an alert will be triggered, notifying you of the issue. |
| Source Filter | - Select Source Host if you want to create the policy for specific flow source(s). - Select Group if you want to create the policy for flow sources that belong to specific groups. - Select Everywhere if you want to create the policy for all the flow sources in the system. This option is selected by default. |
| Source | Select the specific Source Host or Group for which you want to create the policy. This dropdown will show results based on the option you have selected in the previous option. You can leave this field blank if you have selected 'Everywhere' in the previous option. |
| Result By | Specify the grouping criteria for the aggregated values. This field allows you to define how the flow data will be grouped and aggregated for analysis. |
Scenario
Suppose we want to create a flow policy to trigger an alert whenever there is no flow data or very low flow data detected from any particular source.

In this way, we can configure a flow policy to raise an alert.
We will discuss the other conditions for the alert to be triggered now.
| Field | Description |
|---|---|
| Alert Type | - Select Scheduled if you wish to schedule the alert evaluation at specified time(s) in the future. - Select Real Time if you wish to schedule the alert evaluation in real-time as soon as you create the policy |
| Scheduler Type | This option is available only when you select Scheduled as the Alert Type - Select Once if you want the policy evaluation to occur only once. In this case, the policy will evaluate the data from the past hour at the time of evaluation. - Select Daily if you want the policy evaluation to occur daily. The policy will evaluate the data from the past 24 hours at the time of evaluation. - Select Weekly if you want the policy evaluation to occur weekly. The policy will evaluate the data from the past 7 days at the time of evaluation. - Select Monthly if you want the policy evaluation to occur monthly. The policy will evaluate the data from the past 30 days at the time of evaluation.. |
| Start Date | This option is available only when you select Scheduled as the Alert Type. Select the date at which you want to start the policy evaluation. |
| Hours | This option is available only when you select Scheduled as the Alert Type. Select the time(s) at which you want to start the policy evaluation. |
| Days | This option is available only when you select Scheduled as the Alert Type and Weekly as the Scheduler Type. Select the day(s) at which you want to start the policy evaluation. |
| Months | This option is available only when you select Scheduled as the Alert Type and Monthly as the Scheduler Type. Select the month(s) in which you want to start the policy evaluation. |
| Dates | This option is available only when you select Scheduled as the Alert Type and Monthly as the Scheduler Type. Select the date(s) at which you want to start the policy evaluation. |
| Critical/Major/Warning | Kindly use these fields to set the severity under which the alert will be triggered. |
| Supress Action | Switch this Toggle button ON to supress the actions and notifications mapped to the policy. Once you switch this button ON and the alert is triggered, the action will be executed once and you will receive a single notification before the actions and notifications configured in the policy are supressed for the time-period specified in the field Supress Window. |
| Supress Window | Specify the time-period for which you do not wish to execute the actions and receive the notifications mapped to policy. |
Set Alert Message
| Field | Description |
|---|---|
| Subject | Modify the subject-line for the alert message. |
| Message | Modify the alert message from here. |
For a list of default supported Macros to modify the default set message, Please visit: Alert Macros
Notification
| Field | Description |
|---|---|
| To | Add every recipient that should receive the alert. Type an entry, then select from the picker or press Enter to add it as a tag. Supported entry formats: @User for a registered ObserveOps user (delivered by their profile channels), @email@example.com for a direct email address, /Handle for a Microsoft Teams or Slack handle from a saved integration profile, #UserProfile for a saved user profile that fans out to every user inside it, !Profile for a Syslog Forwarder or SNMP Trap Forwarder integration profile that forwards the alert to an external destination. |
| + Bcc | Select + Bcc at the end of the To field to open a BCC field below it. Recipients you add in the BCC field stay hidden from every other recipient. Applies to email notifications only. |
| Play Sound | Activate this toggle to enable sound notifications when an alert is triggered. |
| If Severity is | Choose the severity level at which the sound notification should be triggered. This option becomes visible only when the Play Sound toggle is switched ON. |
The first recipient in To goes into the email To header and is visible to every other recipient. Set it to a team or distribution address such as noc@company.com for privacy. See Notification for the full BCC behaviour.
Take Action
| Field | Description |
|---|---|
| Action to be taken | Select a runbook from the dropdown to be executed when the alert is triggered. |
| Create New | Select this button to start creating a new runbook which you might want to assign to the policy you are creating. |
When you select a Top 10 Process runbook (Linux, Windows, or Solaris variant) in Action to be taken, ObserveOps first sends the standard alert notification email using the current template, then sends a separate follow-up email that contains the Top 10 Process details returned by the runbook. Both emails go to the recipients listed under Notification.
Declare Incident
| Field | Description |
|---|---|
| Select Integration Profile to Trigger | Choose an Integration profile to be executed from the dropdown when the chosen alert severity is triggered. |
| When Alert Severity is | Select an Alert severity from the dropdown. |
| Create Integration Profile | Select this button to start creating a new Integration profile that you might want to assign to the policy you are creating. |
You can click on to define a new Alert severity and Integration Profile combination. You can have separate Integration profile triggered at different levels of Alert severity.
Select the Create Policy button to create the policy based on the details entered.
Select the Reset button to erase all the current field values, if required.