Network Flow Logs
Network Flow Logs (also referred to as flow data) capture metadata about IP traffic generated by devices across emnify’s mobile core. Use them to observe device connectivity behavior, troubleshoot issues, support security analysis, and meet audit or compliance requirements—without inspecting packet payloads or content.
Flow Logs are a subscribable enterprise service. Access them through the emnify Portal, the REST API, or stream them to external systems using Data Streamer.
Each Flow Log record describes observed IP traffic using core network attributes, including source and destination IP addresses, ports, protocol, timestamps, and traffic volume. Records also include hostname attribution and device, session, and network context (for example, organization, endpoint, APN, and serving operator) where available.
With this enrichment, you can identify not only which IP addresses your devices communicate with, but also which domains and services they contact and under which network context.
Flow Log events
Flow Log records are emitted at defined stages of a flow’s lifecycle, indicated by the event_type field:
A flow is identified by flow_id.
For flow_update records, bytes_up and bytes_down are incremental values for the reporting window from period_start_ts to period_end_ts.
On flow_end, the release_details object explains how and why the flow terminated.
Record fields
Enrichment objects
The following objects are present when the corresponding enrichment is available.
nat_details—NAT translation details:
domain_name—destination name attribution:
pdp_context—mobile network context:
release_details—flow termination details (flow_end only):