| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
A real-time NetFlow visualization tool that displays network traffic on an interactive world map. Built with Go and designed for use with firewalls and routers that support NetFlow v9.
NetFlowMap was developed entirely with AI as an exploratory project. There might be dragons. 🐉
The easiest way to run NetFlowMap:
Download example configuration
curl -O https://raw.githubusercontent.com/RiskIdent/NetFlowMap/main/configs/config.example.yml
mv config.example.yml config.yml
# Edit config.yml with your settingsRun the container
docker run -d \
-p 8080:8080 \
-p 2055:2055/udp \
-v $(pwd)/config.yml:/app/config.yml:ro \
ghcr.io/riskident/netflowmap:latestAccess the web interface
Open http://localhost:8080 in your browser.
Download the required files
curl -O https://raw.githubusercontent.com/RiskIdent/NetFlowMap/main/docker-compose.yml
curl -O https://raw.githubusercontent.com/RiskIdent/NetFlowMap/main/configs/config.example.yml
mv config.example.yml config.yml
# Edit config.yml with your settingsStart with Docker Compose
docker compose up -dAccess the web interface
Open http://localhost:8080 in your browser.
| Port | Protocol | Description |
|---|---|---|
| 8080 | TCP | Web UI |
| 2055 | UDP | NetFlow collector |
| Path | Description |
|---|---|
| config.yml | Your configuration (required) |
| users.yml | Local user credentials (optional) |
| netflowmap-data | GeoIP database storage (persistent) |
To change ports, edit docker-compose.yml:
ports:
- "8080:8080" # Change left side for different host port
- "9995:2055/udp" # Example: Use port 9995 for NetFlowClone the repository
git clone https://github.com/RiskIdent/NetFlowMap.git
cd NetFlowMapCreate configuration
cp configs/config.example.yml config.ymlBuild and run
go build -o netflowmap ./cmd/netflowmap
./netflowmapAccess the web interface
Open http://localhost:8080 in your browser.
See configs/config.example.yml for a complete configuration example.
Each source represents a device sending NetFlow data to NetFlowMap:
sources:
- id: "fw-main"
name: "Main Firewall"
source_ip: "192.168.1.1" # IP address of the NetFlow exporter
latitude: 52.52 # Geographic location for map display
longitude: 13.405flows:
# How long flows remain visible after last update (seconds)
display_timeout_seconds: 60
# Maximum number of flows to display (sorted by bandwidth)
max_display_flows: 100Configure the log level in config.yml:
log_level: info # Options: trace, debug, info, warning, error| Level | Description |
|---|---|
| trace | Very verbose, includes per-flow details |
| debug | Debug information, filter operations |
| info | Normal operation messages (default) |
| warning | Warnings only |
| error | Errors only |
If your NetFlow exporter uses packet sampling (e.g., 1:100), NetFlowMap can detect this automatically via NetFlow Options Templates. As a fallback, you can configure it manually:
sources:
- id: "fw-main"
name: "Main Firewall"
source_ip: "192.168.1.1"
latitude: 52.52
longitude: 13.405
sampling_interval: 100 # 1:100 samplingWhen sampling is detected, an "Extrapolate sampled data" toggle appears in the UI to estimate real traffic values.
Resolve remote IP addresses to FortiGate address object names:
sources:
- id: "fw-main"
name: "Main Firewall"
source_ip: "192.168.1.1"
latitude: 52.52
longitude: 13.405
fortigate:
host: "https://192.168.1.1"
token: "your-api-token"
verify_ssl: falseNetFlowMap supports optional authentication with role-based access control.
| Role | Access Level |
|---|---|
| Admin | Full access to all data including private IPs |
| User | Access to public IPs only, private IPs are masked |
| Anonymous | Can view the map but all IP addresses are hidden |
Generate a password hash
With Docker Compose:
docker compose run --rm netflowmap --hash-passwordWith local binary:
./netflowmap --hash-passwordYou will be prompted to enter and confirm your password (input is hidden).
Create users.yml
cp configs/users.example.yml users.ymlAdd users to users.yml
users:
- username: admin
role: admin
password_hash: "$2a$10$..."
- username: viewer
role: user
password_hash: "$2a$10$..."Enable authentication in config.yml
auth:
enabled: true
session_secret: "your-secret-key-min-16-chars"
session_duration: 12h
local:
enabled: true
users_file: "users.yml"Connect to an OpenID Connect provider (Keycloak, Authentik, etc.):
auth:
enabled: true
session_secret: "your-secret-key-min-16-chars"
session_duration: 12h
oidc:
enabled: true
issuer_url: "https://auth.example.com/realms/main"
client_id: "netflowmap"
client_secret: "your-client-secret"
redirect_url: "http://localhost:8080/auth/callback"
admin_users:
- "admin@example.com"
- "kai"Use the "Min. Traffic" slider to filter out small connections and focus on large data transfers. The slider supports values from 0 (disabled) up to 1 GB.
Search for flows by:
Click on a remote IP marker (green dot) to see:
Click the "Health" button in the header to view:
The dashboard auto-refreshes every 10 seconds.
NetFlowMap/ ├── cmd/netflowmap/ # Application entry point ├── internal/ │ ├── auth/ # Authentication (local + OIDC) │ ├── config/ # Configuration parsing │ ├── flowstore/ # In-memory flow storage │ ├── fortigate/ # FortiGate API client │ ├── geoip/ # GeoIP database management │ ├── logging/ # Structured logging │ ├── netflow/ # NetFlow v9 collector & parser │ └── web/ # HTTP server, handlers, WebSocket ├── web/ │ ├── static/ # CSS, JavaScript │ └── templates/ # HTML templates ├── configs/ # Example configurations └── data/ # GeoIP database files
MIT License - see LICENSE file for details.
For information about third-party components and their licenses, see LicenseInfo.md.
Contributions are welcome! Please open an issue or submit a pull request.
| Back | FazBrowse Home | New Git URL |