On Linux, ntopng has the ability to provide visibility into the processes which are responsible for the generation of traffic flows. Process and other process-related metadata is attached to traffic flows. To enable this feature, ntopng needs to be used in combination with nProbe Agent (see Using ntopng with nProbe Agent). For additional details, please refer to blog posts:
- System-Introspected Network and Container Visibility: A Quick Start Guide
- Introducing libebpfflow: packet-less network traffic and container visibility based on eBPF and referenced articles.
An nProbe Agent license is required.