It includes payload and protocol data, plus observable endpoints, ports, timing, size, direction, and treatment. Its exact meaning depends on the layer and observation point being discussed.
Traffic may be observed through packet capture, flow records, interface counters, protocol logs, or purpose-built sensors. Packets preserve more detail; flows summarize packets sharing defined properties; counters aggregate still further. These observations can become security telemetry when they are collected and used as evidence for detection, investigation, assurance, or response; retention and enrichment depend on the use case.
Key points
Operational useTraffic observations support capacity planning, troubleshooting, policy verification, incident investigation, and detection of behavior that differs from a baseline.
Collection designPlace observation points according to the question being answered, synchronize time, document filtering and sampling, protect collectors, and validate that expected traffic can reach them.
Privacy and governanceNetwork content and metadata can reveal communications, relationships, locations, and user behavior. Establish authority, purpose, notice where applicable, access controls, minimization, retention, and secure disposal before monitoring.
Important limitationNo observation point provides complete truth. Encryption limits content visibility; tunneling, asymmetric routing, segmentation, sampling, sensor overload, and packet loss create gaps. Unusual traffic is a lead for analysis, not proof of malicious activity.