Version 13.1
- Last Updated: September 16, 2026
- 11 minute read
- Flowmon Products
- Flowmon
- Documentation
Introduction
Progress® Flowmon® 13.1 delivers new features and improvements to enhance analytical capabilities and the user experience:
- New interactive chart visualizations for Advanced Analysis results, including the Bar chart and Sankey diagram, together with updated versions of the existing Pie chart and In time chart.
- MSS (Maximum Segment Size) field support in flow data, to help identify non-standard link connections and network performance issues.
- TCP Retransmission and Out-of-Order NPM statistics now expressed as percentage rates for easier interpretation.
- Investigation Playbooks and Automations to standardize, reuse, and automatically execute investigation workflows.
- Application Identification to enrich flows with application name and cloud platform information for clearer application-level visibility.
- IP address support on monitoring ports of hardware appliances equipped with 10/25/100GbE NICs.
- Configurable Forward Error Correction (FEC) mode on monitoring ports of hardware appliances equipped with 10/25/100GbE NICs.
- Extended packet filter syntax for the Suricata plugin.
Before proceeding with the update, review the following sections in this document carefully:
These sections provide an overview of installation requirements, update constraints, known issues, and the installation process.
Let us know your feedback
Customers helped to choose and validate some of the features that went into this release and we want to hear from you to continue to improve Flowmon. You can request to join and participate in pre-release activities on the Flowmon Customer Validation Program (CVP) and vote for and submit your product ideas on our ideas portal. Thank you for helping to make Flowmon better!
Release history
- 13.1.0: Released 16th September 2026
What is new in Flowmon 13.1?
Advanced Analysis charts
The Advanced Analysis results panel now includes a new interactive chart panel with multiple visualization types:
- Pie chart — The default view, showing top results as proportional slices.
- Sankey diagram — Visualizes traffic flows across multiple columns to reveal relationships between fields such as source IP, destination IP, and port.
- In time chart — Displays results as a line chart over time, with support for volumetric metrics (Flows, Packets, Traffic), NPM metrics, retransmission, and linear or logarithmic axis scaling.
- Bar chart — Displays the top 10 results as horizontal bars sorted by the selected metric.
For more information, refer to Advanced Analysis Charts.
MSS field support
Flowmon now collects and exports the TCP Maximum Segment Size (MSS) as a flow field. MSS is related to the Maximum Transmission Unit (MTU) and helps you identify non-standard link connections and mismatched end-point configurations, which can cause network performance problems and a high number of out-of-order packets.
TCP Retransmission and Out-of-Order rates shown as percentage
The NPM statistics for TCP Retransmission and Out-of-Order are now available as percentage rates: Retransmission Rate [%] (RTR) and Out of Order Rate [%] (OoO). These replace the old average values in most places across the interface, including Advanced Analysis, Top Chapters, Alerts, and Dashboards and Reports.
Investigation Playbooks and Automations
Progress Flowmon Dashboards and Reports now supports Playbooks and Automations, a new way to standardize and reuse investigation workflows in the Monitoring Center Analysis view:
- Playbooks are reusable investigation templates. You can save an existing investigation as a playbook, including its steps, filters, and variables, and then create new, independent investigations from it at any time.
- Automations extend playbooks with automatic execution. You can configure an automation to run a playbook on a schedule, or trigger it automatically when the Anomaly Detection System (ADS) detects a specific event, so that investigation results are ready as soon as an incident is detected.
- Each automation step is logged with its inputs, outputs, and results, so you can review, re-run individual steps, or re-run an entire playbook without repeating manual work.
For more information, refer to Playbooks and Automations.
Application Identification
A new processing module extends flow-based monitoring with application-level visibility. It enriches flow records with the identified application name and cloud platform, using an application identification database that matches flows against known IP addresses and subnets associated with specific applications and cloud services. The added cloud-application and cloud-platform fields can be used for filtering, grouping, and reporting in Advanced Analysis, Dashboards, and Reports. This feature requires a valid, non-expired Flowmon support contract.
For more information, refer to Application Identification.
IP Address Support on Monitoring Ports
On supported Flowmon hardware appliances equipped with 10/25/100GbE NICs, you can now assign an IPv4 or IPv6 address to a monitoring port even when the interface is accelerated using DPDK. Previously, assigning an IP address to a monitoring port was blocked on all DPDK-accelerated monitoring ports. This restriction remains in place on appliances equipped with older-generation monitoring NICs.
Configurable FEC on Monitoring Ports
You can now configure the Forward Error Correction (FEC) mode for monitoring ports on supported Flowmon hardware appliances equipped with 10/25/100GbE NICs using either the web interface or the CLI. FEC helps detect and correct transmission errors on high-speed network links, allowing you to align the FEC settings with connected devices and improve link reliability in environments where transmission errors may occur.
Extended packet filter syntax for the Suricata plugin
The packet filter syntax for the Suricata plugin (used by the IDS Probe module) has been significantly extended, and is now similar to the packet filter syntax used when creating Flowmon Packet Investigator (FPI) Probe recordings. The extended syntax adds the following capabilities:
- IPv6 address and subnet matching, in addition to IPv4.
- MPLS label matching, including ranges and absence matching (no MPLS label present).
- MAC address matching.
- Port and protocol matching (TCP, UDP, ICMPv4, ICMPv6).
- Negation (
not) and grouping with parentheses, in addition toandandor. - Inner and outer scoping for VLAN and MPLS rules, to match a specific tag on packets carrying multiple VLAN or MPLS layers.
- Comments in filter files (any text after
#on a line is ignored).
Existing Suricata filter files continue to work without changes.
Other changes - Flowmon 13.1.0
- The OS kernel was updated to version 5.14.0-687.42.1.el9_8, fixing CVE-2026-31411, CVE-2026-31402, CVE-2026-31408, CVE-2026-23401, CVE-2025-68724, CVE-2026-31419, CVE-2026-31508, CVE-2026-31669, CVE-2026-31613, CVE-2026-43037, CVE-2026-31772, CVE-2026-43038, CVE-2026-23243, CVE-2026-43125, CVE-2026-43116, CVE-2026-43198, CVE-2026-43233, CVE-2026-43279, CVE-2026-31474, CVE-2026-43329, CVE-2026-43503, CVE-2026-31488, CVE-2026-46145, CVE-2026-46150, CVE-2026-46116, CVE-2026-46117, CVE-2026-46120, CVE-2026-46155, CVE-2026-46125, CVE-2026-46135, CVE-2026-46173, CVE-2026-46152, CVE-2026-46166, CVE-2026-46181, CVE-2026-46176, CVE-2026-46086, CVE-2026-46189, CVE-2026-46215, CVE-2026-46056, CVE-2026-43414, CVE-2026-45852, CVE-2026-45898, CVE-2026-45984, CVE-2026-46054, CVE-2026-46090, CVE-2026-43276, CVE-2026-46243, CVE-2026-46242, CVE-2026-46259, CVE-2026-46316, CVE-2026-46331, CVE-2026-53268, CVE-2026-53131, CVE-2026-53006, CVE-2026-52976, CVE-2026-53016, CVE-2026-53059, CVE-2026-53071, CVE-2026-53264, CVE-2026-52924, CVE-2026-52923, CVE-2026-52920, CVE-2026-53266, CVE-2026-43114, CVE-2026-53185, CVE-2026-52950, CVE-2026-52991, CVE-2026-53189, CVE-2026-53281, CVE-2026-23003, CVE-2026-23191, CVE-2026-46113, CVE-2026-53359, CVE-2026-23204, CVE-2026-43499, CVE-2025-71066, CVE-2026-23209, CVE-2026-23193, CVE-2026-22998, CVE-2026-23231, CVE-2026-23001, CVE-2026-23171, CVE-2025-40026, CVE-2026-64277, CVE-2026-64189, CVE-2026-64530, CVE-2026-64191, CVE-2026-64600, CVE-2026-64276, CVE-2026-63888, CVE-2026-64017, CVE-2026-63824, CVE-2026-64048, CVE-2026-64531, CVE-2026-64560, CVE-2026-64268, CVE-2026-64379, CVE-2026-64387, CVE-2026-64368, CVE-2026-43237, CVE-2025-38106, CVE-2025-40096, CVE-2026-64386, CVE-2026-64382, CVE-2026-53356, CVE-2026-45878, CVE-2026-53143, CVE-2026-64561, CVE-2026-23415, CVE-2026-68343, CVE-2026-68388, CVE-2026-68145, CVE-2026-53202, CVE-2026-64007, CVE-2026-63952, and CVE-2026-74581.
- The aardvark-dns package was updated to version 1.17.1-1.el9_8, fixing CVE-2026-35406.
- The acl package was updated to version 2.4.0-1.el9_8, fixing CVE-2026-54369.
- The axios library was updated to version 1.19.0, fixing CVE-2026-67312, CVE-2026-67313, CVE-2026-67314, CVE-2026-67315, CVE-2026-67316, CVE-2026-67317, CVE-2026-67318, CVE-2026-67319, CVE-2026-67320, and CVE-2026-67321.
- The brace-expansion library was updated to versions 1.1.18, 2.1.4, and 5.0.9, fixing CVE-2026-13149, CVE-2026-14257, and CVE-2026-69152.
- The capstone package was updated to version 4.0.2-13.el9_8, fixing CVE-2025-68114 and CVE-2025-67873.
- The coreutils package was updated to version 8.32-41.el9_8, fixing CVE-2025-5278.
- The dompurify library was updated to version 3.4.13, fixing CVE-2026-65898, CVE-2026-65899, and CVE-2026-65900.
- The dracut package was updated to version 057-120.git20260728.el9_8, fixing CVE-2026-15816.
- The echarts library was updated to version 6.1.0, fixing CVE-2026-45249.
- The expat package was updated to version 2.5.0-6.el9_8.1, fixing CVE-2026-45186.
- The extract-zip library dependency was removed by pinning @puppeteer/browsers to version 3.2.0, fixing CVE-2026-56876.
- The form-data library was updated to version 4.0.6, fixing CVE-2026-12143.
- The glib2 package was updated to version 2.68.4-19.el9_8.9, fixing CVE-2025-14512, CVE-2025-14087, and CVE-2026-58016.
- The gnutls package was updated to version 3.8.10-8.el9_8, fixing CVE-2026-33846, CVE-2026-33845, CVE-2026-3833, CVE-2026-42011, CVE-2026-42009, CVE-2026-42015, CVE-2026-42012, CVE-2026-42013, and CVE-2026-5260.
- The immutable library was updated to version 4.3.9, fixing CVE-2026-59879 and CVE-2026-59880.
- The ip-address library was updated to version 10.5.0, fixing CVE-2026-54272, CVE-2026-69192, and CVE-2026-69198.
- The jq package was updated to version 1.6-19.el9_8.2, fixing CVE-2026-40164 and CVE-2026-39979.
- The js-yaml library was updated to version 4.3.1, fixing CVE-2026-59869 and CVE-2026-59870.
- The krb5-libs package was updated to version 1.21.1-10.el9_8, fixing CVE-2026-40355.
- The libarchive package was updated to version 3.5.3-11.el9_8, fixing CVE-2026-4111.
- The libpng package was updated to version 1.6.37-15.el9_8.2, fixing CVE-2026-33636, CVE-2026-33416, CVE-2026-25646, CVE-2026-22695, and CVE-2026-22801.
- The libssh package was updated to version 0.10.4-18.el9, fixing CVE-2026-0966.
- The libxml2 package was updated to version 2.9.13-14.el9_8.2, fixing CVE-2025-6170 and CVE-2024-34459.
- The NetworkManager package was updated to version 1.54.3-5.el9_8, fixing CVE-2026-10805.
- The openssh package was updated to version 9.9p1-9.el9_8, fixing CVE-2026-35414, CVE-2026-55655, CVE-2026-55653, and CVE-2026-59996.
- The pcp package was updated to version 6.3.7-8.el9_8.4, fixing CVE-2026-16526, CVE-2026-16524, CVE-2026-16529, and CVE-2026-16527.
- The perl-Archive-Tar package was updated to version 2.38-6.el9_8.2, fixing CVE-2026-42496.
- The PHP package was updated to version 8.5.10-1.el9.remi.
- The podman package was updated to version 5.8.2-6.el9_8, fixing CVE-2026-34986, CVE-2026-32280, CVE-2026-32283, CVE-2026-42508, CVE-2026-39832, CVE-2026-39835, and CVE-2026-39822.
- The protobuf package was updated to version 3.14.0-17.el9_7, fixing CVE-2026-0994.
- The python3.12 package was updated to version 3.12.14-1.el9_8, fixing CVE-2026-6100 and CVE-2025-59375.
- The qemu-guest-agent package was updated to version 10.1.0-17.el9_8.5, fixing CVE-2026-48914.
- The react-router library was updated to version 7.18.2, fixing CVE-2026-53666, CVE-2026-53667, CVE-2026-53669, and CVE-2026-55685.
- The sg3_utils package was updated to version 1.47-10.el9_8.1, fixing CVE-2026-16313.
- The sqlite package was updated to version 3.34.1-11.el9_8, fixing CVE-2026-11824 and CVE-2026-11822.
- The sssd package was updated to version 2.9.8-4.el9_8.1, fixing CVE-2026-14476 and CVE-2026-14474.
- The systemd package was updated to version 252-67.el9_8.4, fixing CVE-2026-29111.
- The vim package was updated to version 8.2.2637-26.el9_8.13, fixing CVE-2026-41411, CVE-2026-34982, CVE-2026-47162, CVE-2026-25749, CVE-2026-55693, CVE-2026-52858, and CVE-2026-47167.
Fixed issues
Issues fixed in Flowmon 13.1.0
| Ticket Number | Issue Topic | Issue Details | Resolution Details |
|---|---|---|---|
| - | Monitoring Center | When restoring a full system backup that included 1-minute or 30-second shadow profiles, the profile start time was not preserved and was displayed as the time of the restore instead of the original start time. | Shadow profile start time for 1-minute and 30-second profiles is now correctly restored from the backup after a disaster recovery restore. |
| - | Collector | In rare cases, performing multiple module package operations at the same time could leave the package manager in an inconsistent internal state, potentially causing module installation or update issues. | Concurrent module package operations are now properly synchronized, preventing inconsistent internal state in the package manager. |
| 01879347 | Monitoring Center | Updating flow sources with SNMPv2 enabled could crash the scheduled source update process when the SNMP query returned an error other than the expected "cannot read SNMP" response. | The scheduled source update process now handles all SNMP error responses gracefully and no longer crashes. |
| 01921941 | Monitoring Center | A user with write access to a dashboard shared by another user could not move that dashboard from hidden to visible, and the action failed with a permission error. | Users with write access to a shared dashboard can now move their own instance of the dashboard between hidden and visible. |
| 01930433 | Update/Installation | When management interface 2 was not present on the appliance, the exported XML configuration contained an invalid warning entry for management interface 2 instead of omitting it, which could confuse the import process on re-import. | The exported XML configuration now omits the management interface 2 entry when the interface is not present, and importing such a configuration no longer produces errors or warnings. |
| 01934288 | Collector | The Supported Flow Standards specification document referred to a Flow Database Fields configuration option in Configuration Center that is no longer available in Flowmon 13. | The Supported Flow Standards specification document was updated to clarify that the Collector now stores all flow fields exported by the Probe by default, without requiring any Collector Configuration setting. |
| 01939270 | Collector | Adding a new flow source could cause flow drops due to reduced Collector processing performance. | Collector performance after adding a new flow source was improved to prevent flow drops. |
| 01939301 | Collector | After an out-of-memory condition occurred during a long-running aggregation query, the query process could become unresponsive and required manual intervention to recover. | The query process no longer becomes unresponsive after encountering an out-of-memory condition. |
Important information
Update package availability
Newly announced Flowmon releases may not appear immediately on the Versions page because the update package rollout is gradual. Update packages are initially available on the Progress Community Portal, while automatic update availability is enabled progressively across systems. Systems enrolled in the Flowmon Beta program receive immediate access.
System requirements and update constraints
To successfully install and operate Flowmon 13.1.0, your environment must meet the following requirements:
Minimum source version
The update to Flowmon 13.1.0 is only possible from Flowmon 13.0.8 or later. If any installed module is not updated to its required minimum version, or if a module migration has not completed, the installer blocks the update and lists all failed checks.
After a successful update to Flowmon 13.1.0, the /data/backup directory and its associated backup quota are removed. You are notified of this cleanup through a system notification.
Known issues and limitations
Features not available in 13.1.0
The following features will be available in some later release:
- Backup for Disaster Recovery
- Flow Quality Analyzer tool
- Self-health check script
Azure virtual machines with Accelerated Networking enabled are not supported.
Flowmon 13.1.0 cannot identify the network interface correctly on these virtual machines because Azure presents a synthetic interface and an SR-IOV Virtual Function that share the same MAC address. Select an instance size that does not support Accelerated Networking, or disable Accelerated Networking on the network interface.
Refer to Supported Azure instance sizes. This limitation is tracked for resolution in a later Flowmon 13.1.x release. This limitation is distinct from the Azure interface issue that was resolved in Flowmon 12.5.
Release information and installation
Flowmon
Version: 13.1.0
Release date: 16th September 2026
This package contains an update for Flowmon appliances.
Copyright notice
Copyright © 2007 - 2026 Progress Software Corporation and/or its subsidiaries or affiliates. All Rights Reserved.
Support information
If you need help, contact our Support team at the Flowmon Support and Learning Hub.
Compatibility
Version 13.1.0 and higher is compatible with the following modules:
- Flowmon ADS 13.1.0
- Flowmon Packet Investigator 13.1.0
- Flowmon Packet Investigator Probe 13.1.0
- Flowmon APM 13.1.0
- Flowmon APM Probe 13.1.0
- Flowmon IDS Probe 13.1.0
- Flowmon Data Retention 13.1.0
If an incompatible version of any module is installed on a Flowmon appliance, it will be stopped and disabled during the update to Flowmon version 13.1.x. When a compatible version of the module is installed, the module will be automatically enabled and started again.
Installation requirements
Some installation requirements to be aware of are as follows:
- The Flowmon appliance must be updated to version 13.0.8 or newer before you can apply this update.
- Before you start updating the Flowmon appliance to version 13.1.x, ensure the installed modules meet the following version requirements:
- Flowmon ADS 13.0.0
- Flowmon Packet Investigator 13.0.0
- Flowmon Packet Investigator Probe 13.0.0
- Flowmon APM 13.0.0
- Flowmon APM Probe 13.0.0
- Flowmon IDS Probe 13.0.0
- Flowmon Data Retention 13.0.2
- If any version is older than the ones specified above, the update will not start.
Installation
For the automatic package download from services.flowmon.com:
- Log in to the Configuration Center on your Flowmon appliance.
- Select the Versions tab.
- Click Update the Package List.
- If the Flowmon update package is available, Flowmon OS appears in the list.
- Click Install for the Flowmon OS package.
Or, for the manual package download from the Progress Community Portal:
- Download the package from the Progress Community portal. Do NOT unpack it.
- Log in to the Configuration Center on your Flowmon appliance.
- Select the Versions tab.
- Click Import Package and select the update file you downloaded in step 6.
The remaining installation steps are common for both paths:
- When you start the update, the system checks if your appliance is ready. If the system finds any issues, you will see a popup warning that shows the number of failed checks and a bell notification with details about each issue.
- During the installation, all users are logged out and Flowmon may become briefly unavailable and respond with Server Error - 500.
The User interface (UI) switches to maintenance mode during the update. The maintenance page displays the update status and the rest of the entire Flowmon UI is inaccessible for all users until the update completes.
- Wait until a notification is displayed informing you that the update was successful.
The device reboots during the update process.
DO NOT POWER OFF THE MACHINE during the update and reboot process.