Netmon Docs · Product Guide

Visual Network Explorerv7.0.20

See the network whole: a live map built from observed traffic, backed by a sortable conversation ledger — for the questions no single device dashboard can answer.

The Visual Network Explorer (VNE) draws your network as a live map: devices as nodes, observed relationships as edges, with traffic volume expressed in the connections between them. Where a device dashboard answers questions about one box, VNE answers the questions between boxes — what talks to what, through what, and how much.

The Visual Network Explorer showing devices as colored nodes joined by weighted edges, with a toolbar of search, filter, and time controls
The Visual Network Explorer.

Reading the map

Nodes carry the device icon and status coloring you know from the rest of the product; unknown-but-observed hosts appear alongside managed devices, so the map reflects the network you have, not just the one you imported. Edge thickness and the traffic-size legend translate observed volume into visual weight — a saturated uplink is literally the heaviest line on the page.

The toolbar provides search, filtering, and a time control: rewind the map to see what the network looked like during last night’s backup window, or narrow it to one device’s neighborhood when a hundred nodes are ninety-nine too many.

Two views of the same data

The Visual / Table toggle at the top switches between the map and a conversation ledger: every observed conversation as a row — start time, source, destination, service, size, duration — sortable and pageable. The map is for seeing shape; the table is for pinning down the specific conversation the shape made you suspicious of. Both views cover the same time window, so toggling between them keeps your investigation’s context.

The VNE Table view listing observed conversations as rows with start time, source, destination, service, size, and duration columns
The Table view: the map’s conversations as a ledger.

Working from the map

The map is an investigation surface, not a poster:

What feeds it

VNE composes everything the appliance observes: the device inventory, ARP and discovery activity, and the traffic record — the appliance’s own continuous packet inspection first, extended by any NetFlow/sFlow your routers and firewalls export. The map’s completeness therefore follows from placement and configuration: an appliance fed by a SPAN port draws its local segments in full detail by itself, and flow export fills in the segments it cannot see directly. If a region of your network shows as sparse, Installation & First Sign-In (placement) and your flow-export configuration are the levers.