What is New in Flowmon 13.1 and Flowmon ADS 13.1

Default Blog Top Image
by Filip Cerny Posted on September 16, 2026

Improvements to the Progress Flowmon product family continue, and we are pleased to announce the release of Flowmon 13.1.  

The latest 13.1 release builds on the strong foundations we laid in Flowmon 13. Headline enhancements include a rebuilt visualization layer, automated investigation workflows and a set of AI-assisted capabilities in the Flowmon Anomaly Detection System (ADS). 

And the Flowmon team is eager to share how your team can utilize these new capabilities.  

From Static Charts to Interactive Visual Analysis

Flowmon 13.1 replaces the visualizations on the Analysis page with a new visualization layer. You can now visualize flow data using new bar charts and Sankey diagrams. The Sankey view is particularly well suited to IP conversations, mapping traffic flow between sources and destinations at a glance. As shown in the image below. 


 

The new visualization features enable teams to: 

  • Spot Issues Faster - Clear, interactive charts make anomalies, outliers and unusual communication paths obvious at a glance. Patterns that take several queries to uncover in a table appear immediately in a chart. 
  • Work the Same Way Everywhere - The new visuals remain consistent across analyses, dashboards, reports and investigations. Analysts can now move between contexts without relearning how to interpret the data in front of them. 
  • Move Faster Every Day - The visuals load more quickly and respond more smoothly, so exploring large datasets no longer means waiting between clicks. 

Taken together, these changes reduce the time required to understand complex network relationships and help teams make decisions with greater confidence. 

From Repetitive Clicks to Reusable Playbooks 

Network troubleshooting often follows a standard sequence of steps. An analyst runs a query, filters the results, drills into a subset and then repeats the pattern for the next incident. Flowmon 13.1 introduces automated investigations, enabling teams to capture and reuse common sequences. 

  • Build Once, Run Repeatedly - You can create a workflow in the Investigations interface and save it as a playbook. Running the playbook executes the entire analysis sequence, eliminating the manual clicking that slows root-cause analysis. 
  • Consistent Results Across the Team - Playbooks guide every analyst through the same proven process, regardless of their experience level. A junior team member can follow the same investigative path as your most senior engineer. 
  • Knowledge That Stays with the Team - Capturing best practices in a reusable playbook preserves institutional knowledge that would otherwise reside with individuals who may be out sick or leave for another job. 
  • A Transparent Record - Investigation history shows what each playbook use did and why, enabling analysts to review and explain findings to colleagues or auditors. 

From IP Addresses to Application Names 

Flowmon 13.1 extends application labeling across the entire platform. Rather than reading a list of IP addresses and determining which service sits behind each one, you see the specific SaaS or cloud application directly in the traffic. For example, you can see when a session is connected to M365, Slack, YouTube and many other common services. 

Application labels now appear in IP-related data throughout Flowmon and behave like any other attribute. You can filter on them, build chapters from them, display them in dashboards or reports and raise alerts on them. 

Benefits include:  

  • Accurate Application Context - Identifying business applications no longer requires manually mapping IP ranges to services. 
  • Faster Root-Cause Analysis - When something unusual happens, you know which application or service is involved and can go straight to the root cause. 
  • Clearer View of SaaS and Cloud Usage - Application-level labeling provides visibility into how an organization uses cloud services across their environment. 
  • Richer Reporting and Alerting - Reports and alerts describe activity in terms the business recognizes rather than infrastructure identifiers alone. 

New Improved Graphical Interface for Packet Investigator 

Packet analysis is one of the most powerful troubleshooting tools available to network and security teams, but navigating large volumes of packet data can be time-consuming. Flowmon 13.1 introduces a completely redesigned Packet Investigator interface that makes packet analysis faster, more intuitive and easier to navigate. Explore the new UI in the pictures below. 

What is New in Flowmon ADS 13.1 

The Flowmon ADS is receiving a substantial set of updates in release 13.1, with a particular focus on reducing the manual effort required to interpret and act on security events. ADS 13.1 improvements are outlined below. 

From Raw Events to Plain Language: AI Event Summaries 

Security teams need to make decisions quickly, but interpreting security events often requires correlating multiple sources of information, including flow data, related events and external threat intelligence. Experienced analysts can perform this work manually, but it takes time and specialized expertise. 

Flowmon ADS 13.1 addresses this with AI-generated security event summaries. From the Event Detail page, you request a structured narrative explaining what happened, why it matters and what to do next. The system combines local ADS data with reputation signals and business context, then produces the summary using a RAG-enhanced LLM pipeline designed to meet strict privacy and data-handling requirements. The image below displays a typical AI-generated event summary screen. 

The summary shows five areas: 

  • Executive summary – Answering the question “What it means?” An explanation of the event, the risk it poses and its likely impact.
  • Asset Overview - Who was involved? The parties that communicated, their locations and the protocol they used. 
  • Event Overview - What happened? The sequence of activities, when they took place and the key metrics. 
  • Context correlation - What else is connected? Related events and activity that provide broader context. 
  • Threat Indicators - Why it may be a risk? Signs of suspicious behavior and known risk factors. 

This AI assistant event summary feature helps analysts without deep network security expertise understand an event in simple terms and significantly reduces the detective work required to connect evidence, context and indicators. It also produces summaries you can share with executives and stakeholders without having to translate the technical details yourself. 

Customers with Standard Support can currently generate 10 summaries per week. Those on Extended Support can generate 100 per week. 

From Manual Tuning to Guided Configuration 

As networks evolve, ADS filter configurations must evolve with them. New assets, services and infrastructure changes can gradually reduce filter accuracy if they are not reflected in the configuration.  

Assisted filter tuning in Flowmon ADS 13.1 directly addresses this problem. ADS examines your environment, identifies missed IP addresses and configuration gaps and suggests filter updates. The workflow uses three steps that are under human control: 

  1. Review the list of configuration suggestions. 
  2. Approve or decline each suggestion based on your knowledge of the network. 
  3. Apply the changes. 

Enabling this assisted filter tuning delivers these benefits: 

  • Fewer False Positives - Continuously maintained filters keep detection accurate and reduce alert noise. 
  • Faster Time to Value - Tunings are tailored to each specific environment, reducing configuration effort during deployment and proof-of-concept projects. 
  • Lower Operational Overhead - Automated suggestions reduce the manual review and maintenance typically required for filter upkeep. 
  • Accessible to Every Skill Level - Less experienced users can tune configurations they would not previously attempt, while advanced users complete the same work much more quickly. 

Investigations That Start Themselves 

Security analysts rely on flow analysis to validate findings, understand impact and accelerate response. Building this context often requires navigating through multiple investigation steps and correlating data from different views. Flowmon ADS 13.1 streamlines this process through event-triggered automation. When an event is detected, a playbook automatically executes a predefined flow investigation and makes the results immediately available from the Event Detail page. 

Consider a Direct Denial of Service (DDoS) detection. The moment ADS raises the event, a playbook runs the investigation and answers the questions an analyst would ask next: 

  • Which ports and protocols does the traffic use? 
  • Which IP addresses does the attack target? 
  • What do the first flows show? 
  • Which autonomous system does the attacker use? 
  • Which country does the traffic originate from? 

Automated investigations provide: 

  • Root-Cause Analysis from the First Second - Analysis begins the moment the event occurs, rather than when an analyst picks up the alert. 
  • No Manual Investigation Steps - Automated forensic workflows eliminate the switch to Monitoring Center and the repetitive flow analysis that follows. 
  • Lower Mean Time to Resolution - Ready-to-use investigation results shorten the route from detection to remediation. 
  • Consistent Incident Response - Every investigation follows the defined format, keeping outputs standardized and easy to review. 

 

One Set of Filters for NetOps and SecOps 

Network and security teams have long described the same infrastructure using different terms. Filters defined in Flowmon ADS could not be reused in the Flowmon Monitoring Center, forcing analysts to rebuild the same logic a second time and sometimes introducing inconsistencies between the two. 

Flowmon 13.1 makes ADS filters available for data filtering in Flowmon Monitoring Center (FMC) Analysis. Both teams now query network data through the same lens, using shared filter sets across network and security operations. 

The practical difference shows up in the filters themselves. For example, instead of listing individual IP ranges as follows: 

  • src ip "192.162.6.12" "192.167.2.13" "192.198.6.14" "192.162.6.15" "192.161.5.17" "192.162.6.18" AND dst ip ... 

You can instead write a filter that reflects your logical network topology, such as: 

  • src filter “LAN” AND dst filter “SERVERS” AND NOT filter “DNS”... 

This change gives the following benefits: 

  • Better Collaboration - NetOps and SecOps share network context and terminology, so a request from one team lands with the other in terms that both understand. 
  • Time Saved During Investigations - Reusing existing filter definitions eliminates the need to rebuild them from scratch. 
  • Greater Consistency and Accuracy - Applying the same logic across Flowmon products keeps analysis aligned wherever it is performed. 

Find Out More

To see how Flowmon can deliver actionable insights for your organization in minutes, check out the guided demo to get hands-on experience. In the interactive demo, you can choose multiple use cases inspired by actual customers to understand how the Flowmon solution helps with maintaining reliable and secure networks. 


Filip Cerny

Senior Product Marketing Manager

Filip Černý is a Senior Product Marketing Manager at Progress, where he leads product marketing initiatives for network observability, cybersecurity and infrastructure monitoring solutions. With extensive experience in B2B technology marketing, he specializes in translating complex technical concepts into clear business value for customers, partners and industry stakeholders.
More from the author

Related Products:

Flowmon

Network observability platform with AI-powered detection for cyberthreats, anomalies and fast access to actionable insights for greater network and application performance across hybrid cloud ecosystems.

Overview
Prefooter Dots
Subscribe Icon

Latest Stories in Your Inbox

Subscribe to get all the news, info and tutorials you need to build better business apps and sites

Loading animation