Interactive Event Visualization
- Last Updated: April 5, 2026
- 2 minute read
- Flowmon Products
- Flowmon Anomaly Detection System
- Documentation
The Interactive event visualization view is a view of the network traffic data based on which the event was detected. The view is available for each event detected based on network traffic through the Visualize event context menu item. Similarly to the Event details view, the event details are displayed first in the table to clarify what event is being visualized.
Interactive visualization displays individual IP addresses as nodes and data transmission between the IP addresses as edges. The size of nodes and edges is proportional to the volume of transmitted data and their colors, which range from green to red, are corresponding to the number of flows. Event visualization can be interactively browsed; each node has a context menu marked by the symbol of three dots. Clicking the More data menu item downloads all relevant communication of the IP address. The Info item obtains and displays the details of the network traffic in the form of a moving table. In the case of nodes, it displays a table of aggregated communication with other IP addresses. In the case of inbound traffic, the communication is aggregated based on the source IP address, destination port, and protocol. In the case of outbound traffic, the communication is aggregated based on the destination IP address, source port, and protocol. In the case of the edges, it displays a table of individual data flows that constitute the edge, including details such as the duration of the connection, flags, and the type of service (TOS). The Domain name menu item allows you to display the domain name assigned to the IP address. If the domain name translation is not available, the IP address remains displayed instead.
A special type of node is the so-called aggregation. Aggregation represents a larger number of IP addresses and is visualized as a circle-shaped node. Clicking the "+" button next to the aggregation node displays a list of IP addresses that constitute the aggregation. Selecting any of the displayed IP addresses will exclude it from the aggregation. Furthermore, it is possible to work with the IP address and details of its communication by standard means which are described above.