Free Flow Analytics for Your Network
Understanding what is traversing your network—peak volumes, traffic sources, and timing—is a core responsibility for any network engineer. Cloudflare’s Magic Network Monitoring, formerly Flow Based Monitoring, is designed to answer these questions, and it is now entering early access as a free offering. You can request access through this form.
The product now includes an analytics dashboard, self-serve configuration, and a guided onboarding wizard. It removes the need for physical devices like network TAPs. Because it works with any hardware that exports flow data (such as NetFlow or sFlow), configuration is straightforward: point your router at Cloudflare, and the service aggregates and visualizes the traffic.
Inspecting Traffic with the Analytics Dashboard
The analytics dashboard allows you to filter traffic by protocol, source IP, destination IP, TCP flags, and router IP. You can combine these filters to build a precise picture of your traffic and spot anomalies. For example, you might ask how much ICMP traffic was requested from your speed test server over the past 24 hours. If you want to track network security, you can create any number of these combinations to build an understanding of your network’s baseline.
Setting Per-Prefix Volume Alerts
The service is designed to be customizable. After collecting historical data, the dashboard will show your baseline traffic. You can then establish volumetric threshold alerts for a single IP prefix or a group of prefixes. As your network expands or changes, you can update your configuration to accept data from new routers or destinations without reinstalling any software.
Use Case: Home Lab Speed Test Server
Consider a home lab where you use Magic Network Monitoring to watch a speed test server. You want to know when the server sees peak traffic and how much data it moves, plus whether any malicious actors are trying to reach it. You create a rule that captures traffic destined for the server’s IP. After a week of data, the dashboard reveals peaks on weekday mornings at 450–550 Mbps.
You also notice spikes of 300–350 Mbps occurring at the same time in the middle of the night. Diving into the flow data, you find these spikes all originate from the same IP prefix. Researching the source IPs associates them with malicious activity, so you update your firewall rules to block the traffic.
Use Case: Identifying a Ping Flood
Magic Network Monitoring can also help identify L3, L4, and L7 attacks. In the example of a small business, a Ping (ICMP) Flood begins to ramp up traffic volume. The system sends out an alert—via email, webhook, or PagerDuty—once it notices volumes outside the expected baseline.

The security team can then check the dashboard and confirm the attack type by looking for:
- Traffic volume above historical averages
- An unusually high amount of ICMP traffic
- ICMP traffic from a specific set of source IPs
Once the attack is confirmed, the team can take steps to mitigate it—which often involves using a separate DDoS protection service to filter the traffic before it reaches the network.




