Kentik
Network observability platform company
Kentik is a company that provides a cloud-based network observability platform focused on analyzing network traffic flow data, such as NetFlow and sFlow, at scale for large enterprises, service providers, and cloud-native organizations.…
Definition
Kentik is a company that provides a cloud-based network observability platform focused on analyzing network traffic flow data, such as NetFlow and sFlow, at scale for large enterprises, service providers, and cloud-native organizations. Its platform ingests high volumes of flow and routing data to give network engineers visibility into traffic patterns, capacity trends, and security-relevant anomalies across complex, often multi-cloud network environments.
Overview
Large networks, especially those spanning multiple cloud providers, data centers, and internet peering relationships, generate enormous volumes of traffic flow records that traditional SNMP-based polling tools were not designed to analyze at scale. Kentik was built to ingest and query that flow data, primarily NetFlow, sFlow, and similar protocols alongside BGP routing information, fast enough to support interactive investigation of traffic patterns across networks carrying very high volumes of data. Mechanically, network devices export flow records summarizing traffic between source and destination pairs, and Kentik's platform ingests these records into a big-data-style backend built to handle high cardinality and high volume, enriching each flow with contextual information such as BGP-derived autonomous system paths, geolocation, and cloud provider metadata. Engineers query this enriched flow data through Kentik's interface to answer questions like which applications are consuming the most bandwidth on a given link, which peers or transit providers are carrying the most traffic, or whether a traffic spike correlates with a security event such as a volumetric denial-of-service attack. Kentik differs from SNMP-centric tools like LibreNMS, Cacti, or OpenNMS by focusing on flow-level traffic analysis rather than per-interface counters and device health, giving it much finer granularity into who is talking to whom and over which paths, at the cost of requiring flow-exporting-capable network hardware. It also differs from general-purpose observability platforms by specializing deeply in network and traffic data rather than covering application performance monitoring or infrastructure metrics broadly. In practice, Kentik is used by internet service providers, large enterprises with substantial network footprints, and cloud-native companies operating across multiple cloud providers to understand traffic costs, plan capacity, and detect network-layer security anomalies like distributed denial-of-service traffic, often correlating cloud egress costs with actual traffic patterns to help control cloud networking spend. Its main trade-offs are that its value depends on network hardware capable of exporting flow data, which not all environments have configured or support, and that it is a specialized, commercial platform aimed at organizations with substantial network complexity, making it a less proportionate fit for smaller networks whose monitoring needs are met by simpler SNMP-based tools. The organizations that get the most value from Kentik tend to be ones already grappling with traffic volumes or multi-cloud topologies too complex to reason about from device-level counters alone, where flow-level detail turns an otherwise opaque traffic pattern into an actionable, queryable dataset that engineers can drill into during an active incident rather than reconstructing after the fact.
Key Features
- Ingests high-volume NetFlow and sFlow traffic data at scale
- Enriches flow records with BGP path and geolocation context
- Supports interactive querying of traffic patterns across large networks
- Correlates traffic spikes with security events like DDoS activity
- Analyzes multi-cloud network traffic and associated egress costs
- Cloud-hosted platform built for high-cardinality flow data
- Used for capacity planning across complex network topologies
- Complements rather than replaces SNMP-based device health monitoring