$ cd ~/products/sys/setka
nf sys suite · 3/3
Setka
Real-Time Network Flow Visualizer
Packet capture streamed to the browser over WebSocket and rendered live, so you can watch traffic as it happens rather than reading it afterwards.
- +End-to-end pipeline — Capture to WebSocket to browser
- +Live rendering — Flows drawn as they arrive
- +Process attribution — Mapping flows to processes in progress
view source ↗free
What it does
Setka (Russian for "net") captures live TCP and UDP traffic on an interface, groups the packets into flows and streams them to a browser page as they happen. The whole pipeline runs end to end today:
- Capture: libpcap on the chosen interface, filtered to TCP and UDP
- Enrich: marks each flow inbound or outbound
- Process: aggregates packets into flows and clears idle ones every 60 seconds
- Serve: broadcasts flows over a WebSocket to every open page
Try it
With the server running, curl google.com in another terminal. The flow appears in the page within a second.
Install
# macOS: brew install libpcap · Linux: apt-get install libpcap-dev$ git clone https://github.com/NoamFav/Setka && cd Setka$ sudo go run cmd/netviz/main.go -i en0# then open http://localhost:8080Status
- [x]Capture, flow aggregation and WebSocket streaming
- [x]A minimal live page in the browser
- [ ]Real process attribution through OS APIs (today it guesses from the port)
- [ ]REST endpoints alongside the socket
- [ ]Reverse DNS, GeoIP and a flow graph in the page