What is this?

This knowledgebase contains questions and answers about PRTG Network Monitor and network monitoring in general.

Learn more

PRTG Network Monitor

Intuitive to Use. Easy to manage.
More than 500,000 users rely on Paessler PRTG every day. Find out how you can reduce cost, increase QoS and ease planning, as well.

Free Download

Top Tags

View all Tags

Should I use SNMP, Flow (IPFIX/NetFlow/sFlow) or Packet Sniffing for my monitoring?



I am not sure if I should set up monitoring based on packet sniffers, SNMP or Flow. What are the differences? What do you recommend? Is there a comparison?

cisco flow ipfix netflow packet-sniffing planning router sflow snmp

Created on Feb 12, 2010 4:11:39 PM by  Daniel Zobel [Product Manager]

Last change on Dec 2, 2021 9:20:01 AM by  Maike Guba [Paessler Support] (2,404) 2 1

1 Reply

Accepted Answer



This article applies as of PRTG 22

Comparison of SNMP-based monitoring with flow monitoring and Packet Sniffer-based monitoring

With SNMP, Packet Sniffer, and flow sensors, PRTG offers different means to monitor network traffic. The best solution for you depends on your network and on available resources.


Simple Network Management Protocol (SNMP) is the basic means of gathering bandwidth and network usage data. Monitoring the bandwidth usage of routers and switches port by port is the most common use of SNMP, as well as monitoring device readings such as memory or CPU load.

  • Recommended for most standard situations
  • Does not support differentiation of traffic by service/protocol
  • Causes the least CPU load

Packet Sniffer

Using the Packet Sniffer, PRTG inspects all network data packets that pass through the local system's network card. You can either only monitor the traffic on the PRTG core server system, or you make sure that all network traffic that you want to analyze passes it (for example by connecting it to the port of a switch that is used for monitoring activities).

  • Recommended if differentiation of traffic by service/protocol is desired
  • Creates the highest CPU load on the PRTG core server system
  • In PRTG, you can view Toplists for data from this sensor type

Flows (IPFIX/NetFlow/sFlow/jFlow)

Flows can be used with most Cisco and many other routers to measure bandwidth usage. Although it is the most complex type, it is also the most powerful monitoring option for high-traffic networks.

  • Recommended for high-traffic networks and for advanced users
  • Requires changes in the router's setup: You must tell the router to send the flow packets to the PRTG core server system
  • In PRTG, you can view Toplists for data from this sensor type


Created on Feb 12, 2010 4:20:08 PM by  Daniel Zobel [Product Manager]

Last change on Dec 29, 2022 3:02:03 PM by  Brandy Greger [Paessler Support]

Disclaimer: The information in the Paessler Knowledge Base comes without warranty of any kind. Use at your own risk. Before applying any instructions please exercise proper system administrator housekeeping. You must make sure that a proper backup of all your data is available.