TechnicalDiscussion

HN839: Why Flows, Packets, and DDI are All Critical for Operational Effectiveness (Sponsored)

BlueCat Networks, a DDI provider that acquired LiveAction in 2024, discusses how integrating network observability (flows, packets) with DDI capabilities enables faster troubleshooting, improved collaboration between NetOps and SecOps teams, and better automation of network operations. The integration provides context for understanding both network intent (DNS/DHCP rules) and actual network outcomes (traffic behavior).

Summary

Ryan Grandy, Field CTO at BlueCat, explains how the acquisition of LiveAction transformed BlueCat from a traditional DDI company into an intelligent network operations platform. The combined portfolio includes Integrity (monolithic DDI), Maestro (multi-vendor DDI orchestration), Edge (DNS security), LiveNX (telemetry consumption including flows and SNMP), and LiveWire (packet capture and analytics). Grandy uses the analogy of a phone book (DDI/IPAM) and phone bill (flow records) to illustrate how these data sources complement each other.

The conversation explores how integrating DDI with network observability accelerates troubleshooting by enabling operators to answer the five Ws: who, what, when, where, and why. An example shows how IP addresses can change daily due to DHCP, making it critical to correlate flows and DNS records to understand what happened historically. The platform uses APIs to cross-pollinate data between products and features LiveAssist, an AI-powered virtual engineer that normalizes time-series data from multiple sources to provide unified analysis.

Grandy emphasizes that NetOps and SecOps teams should view themselves as a unified "JustOps" function sharing common language and tools. Security-specific features include Security Insights, which bridges network and security teams by surfacing network telemetry in security-relevant contexts, and Live Assurance for firewall policy analysis. The platform can feed data to SIEMs and SOARs while maintaining traceability back to source tools.

On automation, Grandy argues that DDI is ideal for early automation efforts because it's predictable and rule-based, unlike broader network changes. He advocates for using DDI and observability data to keep CMDBs and systems of record current and living rather than static blueprints. The platform exposes APIs for automation and recently added MCP (Model Context Protocol) servers as improved API wrappers with better documentation.

Packet capture, traditionally resource-intensive and limited to packet experts, is reframed through intelligent filtering using flow data as a guide. Rather than capturing everything or searching blindly through massive PCAPs, operators can use flows to identify exact timeframes and conversations, then retrieve only relevant packets for forensic analysis. This reduces storage overhead, mitigates PII/compliance risks from sharing massive PCAPs, and democratizes packet expertise through AI-assisted analysis.

About this episode

If you think of BlueCat as just an IPAM or DDI company, think again. BlueCat acquired LiveAction in 2024, and since then, they’ve been working to integrate LiveAction’s network observability capabilities with the DDI portfolio. In this sponsored episode, Ryan Grande, Field CTO at BlueCat, is here to dig into how network observability and DDI<a class="excerpt-read-more" href="https://packetpushers.net/podcasts/heavy-networking/hn839-why-flows-packets-and-ddi-are-all-critical-for-operational-effectiveness-sponsored/" title="ReadHN839: Why Flows, Packets, and DDI are All Critical for Operational Effectiveness (Sponsored)">... Read more &#187;</a>

Key Insights

  • Grandy argues that DDI represents the 'fundamental laws of nature' (network intent) while observability shows actual outcomes, and combining them provides understanding that neither alone can deliver.
  • The platform enables historical IP address context through DNS and DHCP records, allowing operators to determine who owned an IP, what device it was, and what they were doing, even when DHCP reassigns addresses daily.
  • Grandy proposes that packet capture has been historically underutilized because deployment is complicated, it requires packet expertise that's rare (1-2 people per organization), and sharing massive PCAPs creates compliance and security risks.
  • The company uses flow data as a filtering mechanism to guide forensic packet searches, transforming packet capture from a resource-intensive haystack search into a targeted microscope view of specific conversations and timeframes.
  • Grandy contends that CMDBs and systems of record fail because they are static snapshots of intent rather than living documents, and DDI/observability data should automatically update these systems to reflect actual network state.
  • The platform's LiveAssist AI analyzes all integrated data sources, performs time normalization across disparate telemetry types, and dynamically presents findings differently depending on which data is actually available.
  • Grandy argues that NetOps and SecOps teams speaking different languages and using different tools creates unnecessary duplication and prevents the collaboration needed to rapidly isolate and resolve incidents.
  • The acquisition strategy reflects a belief that observability without DDI context lacks semantic meaning (just IP addresses), while DDI without observability can't validate whether intent actually resulted in desired outcomes.

Topics

DDI and network observability integrationDNS, DHCP, flows, and packet captures for troubleshootingNetOps and SecOps collaborationNetwork automation and CMDBsAI-assisted network analysisPacket capture strategy and forensicsAPI-driven platform architectureMean Time to Resolution (MTTR) and Mean Time to Innocence (MTTI)

Transcript

Welcome to Heavy Networking. If you've ever told someone they might not get your UDP joke, you're listening to the right podcast. I'm Drew Connery-Mari here with my guest co-host Scott Rabban, and today we're sponsored by BlueCat Networks. Now, if you think of BlueCat as an IPAM or DDI company, this episode is going to help you think again. BlueCat acquired LiveAction in 2024, and since then, they've been working to integrate LiveAction's network observability capabilities with the DDI portfolio. And today, BlueCat's here to dig into how network observability and DDI can work together to help you get a faster mean time to resolution, or better yet, mean time to innocence. We'll also explore how network observability, including…

Full transcript available for MurmurCast members

Sign Up to Access

More from The Everything Feed - All Packet Pushers Pods

Get AI summaries like this delivered to your inbox daily

Get AI summaries delivered to your inbox

MurmurCast summarizes your YouTube channels, podcasts, and newsletters into one daily email digest.