HN839: Why Flows, Packets, and DDI are All Critical for Operational Effectiveness (Sponsored)
BlueCat Networks, a DDI provider that acquired LiveAction in 2024, discusses how integrating network observability (flows, packets) with DDI capabilities enables faster troubleshooting, improved collaboration between NetOps and SecOps teams, and better automation of network operations. The integration provides context for understanding both network intent (DNS/DHCP rules) and actual network outcomes (traffic behavior).
Summary
Ryan Grandy, Field CTO at BlueCat, explains how the acquisition of LiveAction transformed BlueCat from a traditional DDI company into an intelligent network operations platform. The combined portfolio includes Integrity (monolithic DDI), Maestro (multi-vendor DDI orchestration), Edge (DNS security), LiveNX (telemetry consumption including flows and SNMP), and LiveWire (packet capture and analytics). Grandy uses the analogy of a phone book (DDI/IPAM) and phone bill (flow records) to illustrate how these data sources complement each other.
The conversation explores how integrating DDI with network observability accelerates troubleshooting by enabling operators to answer the five Ws: who, what, when, where, and why. An example shows how IP addresses can change daily due to DHCP, making it critical to correlate flows and DNS records to understand what happened historically. The platform uses APIs to cross-pollinate data between products and features LiveAssist, an AI-powered virtual engineer that normalizes time-series data from multiple sources to provide unified analysis.
Grandy emphasizes that NetOps and SecOps teams should view themselves as a unified "JustOps" function sharing common language and tools. Security-specific features include Security Insights, which bridges network and security teams by surfacing network telemetry in security-relevant contexts, and Live Assurance for firewall policy analysis. The platform can feed data to SIEMs and SOARs while maintaining traceability back to source tools.
On automation, Grandy argues that DDI is ideal for early automation efforts because it's predictable and rule-based, unlike broader network changes. He advocates for using DDI and observability data to keep CMDBs and systems of record current and living rather than static blueprints. The platform exposes APIs for automation and recently added MCP (Model Context Protocol) servers as improved API wrappers with better documentation.
Packet capture, traditionally resource-intensive and limited to packet experts, is reframed through intelligent filtering using flow data as a guide. Rather than capturing everything or searching blindly through massive PCAPs, operators can use flows to identify exact timeframes and conversations, then retrieve only relevant packets for forensic analysis. This reduces storage overhead, mitigates PII/compliance risks from sharing massive PCAPs, and democratizes packet expertise through AI-assisted analysis.
About this episode
If you think of BlueCat as just an IPAM or DDI company, think again. BlueCat acquired LiveAction in 2024, and since then, they’ve been working to integrate LiveAction’s network observability capabilities with the DDI portfolio. In this sponsored episode, Ryan Grande, Field CTO at BlueCat, is here to dig into how network observability and DDI<a class="excerpt-read-more" href="https://packetpushers.net/podcasts/heavy-networking/hn839-why-flows-packets-and-ddi-are-all-critical-for-operational-effectiveness-sponsored/" title="ReadHN839: Why Flows, Packets, and DDI are All Critical for Operational Effectiveness (Sponsored)">... Read more »</a>
Key Insights
- Grandy argues that DDI represents the 'fundamental laws of nature' (network intent) while observability shows actual outcomes, and combining them provides understanding that neither alone can deliver.
- The platform enables historical IP address context through DNS and DHCP records, allowing operators to determine who owned an IP, what device it was, and what they were doing, even when DHCP reassigns addresses daily.
- Grandy proposes that packet capture has been historically underutilized because deployment is complicated, it requires packet expertise that's rare (1-2 people per organization), and sharing massive PCAPs creates compliance and security risks.
- The company uses flow data as a filtering mechanism to guide forensic packet searches, transforming packet capture from a resource-intensive haystack search into a targeted microscope view of specific conversations and timeframes.
- Grandy contends that CMDBs and systems of record fail because they are static snapshots of intent rather than living documents, and DDI/observability data should automatically update these systems to reflect actual network state.
- The platform's LiveAssist AI analyzes all integrated data sources, performs time normalization across disparate telemetry types, and dynamically presents findings differently depending on which data is actually available.
- Grandy argues that NetOps and SecOps teams speaking different languages and using different tools creates unnecessary duplication and prevents the collaboration needed to rapidly isolate and resolve incidents.
- The acquisition strategy reflects a belief that observability without DDI context lacks semantic meaning (just IP addresses), while DDI without observability can't validate whether intent actually resulted in desired outcomes.
Topics
Transcript
Welcome to Heavy Networking. If you've ever told someone they might not get your UDP joke, you're listening to the right podcast. I'm Drew Connery-Mari here with my guest co-host Scott Rabban, and today we're sponsored by BlueCat Networks. Now, if you think of BlueCat as an IPAM or DDI company, this episode is going to help you think again. BlueCat acquired LiveAction in 2024, and since then, they've been working to integrate LiveAction's network observability capabilities with the DDI portfolio. And today, BlueCat's here to dig into how network observability and DDI can work together to help you get a faster mean time to resolution, or better yet, mean time to innocence. We'll also explore how network observability, including…
Full transcript available for MurmurCast members
Sign Up to AccessMore from The Everything Feed - All Packet Pushers Pods
NB589: OpenAI Makes Cyber Mess, Wants World to Clean It Up; Cisco Strategizes Infrastructure Identity
Network Break discusses major tech news including NVIDIA's reported $12.9B acquisition of Hugging Face, OpenAI's call for global cyber defense (criticized as a potential sales pitch), and significant partnerships between major cloud providers and AI/infrastructure companies. The episode highlights strong financial results from NVIDIA and Marvell, reflecting massive growth in GPU and AI chip demand.
TNO070: Spec Driven Design (SDD) for NetOps and NetEng
Lasse Haugen, a NetOps engineer from Norway, discusses how Spec-Driven Development (SDD) combined with AI tools like Claude has transformed his approach to network automation and infrastructure projects. He shares practical examples of using SDD to build sustainable, maintainable code while leveraging AI as a collaborative partner rather than a code generator.
D2DO310: Developing Efficient AI Workflows
The podcast discusses the evolution and best practices of using AI coding assistants within DevOps workflows, emphasizing token efficiency, agent memory management using Obsidian, and the importance of sandboxing for security. Tyler Lynch shares insights from his experience with AI agents in coding and automation at IBM.
HW085: Designing Wi-Fi for High-Density Events
The podcast discusses strategies for designing Wi-Fi networks for high-density events, emphasizing the importance of thorough planning, questioning, and on-site validation. Key tools and techniques for optimizing performance under these conditions are also highlighted.
PP121: How CYBR.SEC.CON Builds Community for Learning and Professional Development
The episode features a conversation about CyberSecCon, a community-driven security conference in Houston, and explores the origins and growth of both the conference and the Packet Protector podcast. Key insights include how both platforms aim to foster community and collaboration within the cybersecurity and networking fields.