PRTG Manual: Toplists
Packet Sniffer sensors and Flow (NetFlow, jFlow, sFlow, IPFIX) sensors not only measure the total bandwidth usage, but also break down traffic by IP address, port, protocol, and other parameters. This way, PRTG can identify which IP address, connection, or protocol uses the most bandwidth. PRTG shows the results in toplists.
PRTG analyzes all network packets and collects the bandwidth information for all IP addresses, ports, and protocols. This creates a large amount of analysis data. To reduce the amount of data that is stored, PRTG stores only the top 100 entries of each toplist in the database at the end of a specified toplist period by default.
Toplists are available only for Flow and Packet Sniffer sensors. PRTG displays toplists on the sensor's Overview tab.
For more information about the Overview tab, see the Knowledge Base: What options do I have to review my monitoring data in detail?
By default, there are three preconfigured toplists:
Toplist |
Description |
|---|---|
Top Talkers |
Shows bandwidth usage by IP address. |
Top Connections |
Shows bandwidth usage by connection. |
Top Protocols |
Shows bandwidth usage by protocol. |
- Click one of the toplist names on the sensor's Overview tab, or click
below a toplist, to view a distribution chart and a list of the data in different channels. Depending on the selected toplist, this data can include source and destination IP addresses, source and destination ports, protocols, or kinds of traffic.
- Click an entry in the toplist periods list on the left to view data for a specific time period. The default value is 15 minutes. You can also manually define the start and end time of the toplist period that you want to view. Use the date time picker to enter the date and time. Additionally, several table list options are available.
- Click Print This Toplist to view a printer-friendly version of your toplist and use the print dialog of your browser to print the toplist.
- Click Sensor Overview to return to the selected sensor's Overview tab. To quickly select another toplist of the sensor, click one of the toplist tiles at the top of the page.
- Click Add Toplist on the sensor's Overview tab to create a new toplist. The available settings are the same as when you edit a toplist.
- Click
below a toplist on the sensor's Overview tab and confirm with Delete to delete the toplist.
Click
below a toplist on the sensor's Overview tab to edit a toplist.
Setting |
Description |
|---|---|
Name |
Enter a name to identify the toplist.
|
Toplist Type |
Select the type of toplist:
|
Toplist Fields |
This setting is only visible if you select Custom above. Select the fields that you want to add to the toplist by enabling the checkbox in front of the respective field name. The available fields depend on the sensor. They are different for Packet Sniffer, NetFlow v5, NetFlow v9, IPFIX, and sFlow sensors.
|
Toplist Period (Minutes) |
Define the time span that a toplist period covers in minutes. Enter an integer. When a toplist period is finished, PRTG stores the top results and starts a new toplist period.
|
Top Count |
Define the length of your toplist. PRTG stores only this number of entries for each toplist period. Enter an integer.
|
Reverse DNS Lookup |
Define whether you want to perform a reverse Domain Name System (DNS) lookup for IP addresses that are stored in the toplist:
|
Data Transfer |
Define how the probe sends the toplist data set to the PRTG core server:
|
Memory Limit (MB) |
Define the maximum amount of memory (in megabytes) that the probe uses to collect the connection information. Each toplist adds to the memory consumption of the probe. Increase this value if the number of captured connections is not sufficient. Enter an integer. |
Save your settings. If you change tabs or use the main menu without saving, all changes to the settings are lost.
If you create toplists for data lines with considerable usage (for example, steady bandwidth over 10 megabits per second) or if the traffic is diverse (for example, many IP addresses or ports with little traffic each), consider the following aspects:
- The probe gathers all information that is needed for the toplist in RAM during each toplist period. By default, only the top 100 entries are transferred to the PRTG core server. Depending on the toplist type and the traffic patterns, the toplist can consume many megabytes of memory.
- Define toplist periods that are as short as possible to minimize memory usage. This is especially important when the traffic is highly diverse.
- Memory requirements can grow almost exponentially with each toplist field that you use in the toplist definition (depending on the traffic pattern). Avoid complex toplists for high and diverse traffic. For example, the toplist Top Connections with 5 toplist fields needs much more memory than the toplist Top Talkers with 1 toplist field.
- If you notice high bandwidth usage between the PRTG core server and the probe, try the At end of Toplist period option in the toplist settings.
- If you get Data incomplete, memory limit was exceeded messages, increase the memory limit in the toplist settings but monitor the memory usage of the probe process.
- To increase the performance of a toplist, disable the reverse DNS lookup setting.
- When you work with toplists, be aware that privacy issues can arise for certain configurations of this feature. With toplists, you can track all individual connections of a single system to external networks, and you must make sure that it is legal for you to configure PRTG in this way.
- Note that you can view toplists in the PRTG web interface. You might not want to show lists of domains that are used in your network to others, so restrict access rights to sensors that have toplists.
- Toplist charts, such as those for top connections, are not intended for detailed analysis. Instead, they should indicate whether there is an unusual, larger change in the toplist.
KNOWLEDGE BASE
What security features does PRTG include?
What options do I have to review my monitoring data in detail?


