Jeroen Bezemer, a former colleague of mine created a great way to monitor network traffic on virtual switches, using the NetFlow technical note provided by VMware to set it up and enabling NetFlow on virtual switches. NetFlow is a general networking tool with multiple uses, including network monitoring and profiling, billing, intrusion detection and prevention, networking forensics, and SOX compliance. NetFlow sends aggregated networking flow data to a third?party collector (an appliance or server). The collector and analyzer report on various information such as the current top flows consuming the most bandwidth in a particular virtual switch, which IP addresses are behaving irregularly, and the number of bytes a particular virtual machine has sent and received in the past 24 hours. NetFlow is a mature technology, developed by Cisco, that is widely supported by third?party collectors. NetFlow enables visibility into virtual machine traffic in a virtualized server farm. NetFlow support in ESX Server 3.5 is experimental and supports only a limited set of the standard NetFlow features commonly found on physical switches today. Although the activation of NetFlow should not create stability issues, overall performance of the ESX Server host may be affected.