MAC Monitor Probe

The MAC Monitor probe observes MAC address activity on switches and checks VTEP MAC Tables to ensure accurate EVPN type 2 MAC advertisement integration into the Forwarding Database (FDb). It identifies, validates, and flags missing MAC addresses across all VTEPs. This data is summarized by calculating MAC address discrepancies.

Configuration interface for MAC Monitor probe observing MAC address activity and discrepancies across VTEPs with settings for anomaly alerts and monitoring intervals.

Flowchart showing data processing workflow for analyzing MAC addresses and virtual networks. Includes steps for collecting MAC addresses, analyzing systems across VNIs, identifying missing data, and calculating affected systems and networks.

MAC Monitor Probe Historical Analysis Enhancements

The auto-enabled MAC Monitor Probe now provides historical MAC address analysis across the blueprint. This enhancement helps you investigate MAC address behavior over time and troubleshoot network issues more effectively.

The probe now includes two additional views in the source processor:

  • Time-Series view

  • Snapshot view

These views complement the existing Real-Time view and provide historical visibility into MAC address state changes. For more information about this probe, from the blueprint, navigate to Analytics > Probes. Select the built-in enabled MAC Monitor probe from the list of probes available. From left hand menu, select Mac Address Table stage under Collect MAC addresses'processor.

The MAC Monitor Probe reports the following MAC address states:

  • Expected: The MAC address is learned and present on the system for the associated VNI. This state is available in the Real-Time, Snapshot, and Time-Series views.

  • Missing: The MAC address is not present on the system but is expected based on EVPN information. This state is available in the Real-Time, Snapshot, and Time-Series views.

  • Absent: The MAC address is not present on the system. This state is available only in the Time-Series view.

You can view historical state information for all MAC addresses in a single table. For more detailed analysis, open the detailed view to examine state changes at specific timestamps.

You must select one of the following filters is to view the data:

  • System ID (system_id

  • VN ID (vn_id)

  • MAC (mac)

Time-Series view

The Time-Series view lets you analyze historical MAC address state data for a selected time range. It shows how MAC address states change over time, helping you identify recurring, intermittent, or transient issues.

By default, the system retains up to 30 days of historical data depending on how the retention settings are configured and provided there is sufficient storage is available.

The State column displays MAC address state transitions as discrete events. For example, if a MAC address becomes unavailable because of a network issue and later recovers, the view records each state transition:

Expected → Absent → Missing → Expected

Network monitoring dashboard displaying MAC address information, filtered by MAC addresses and VN ID. Table shows details including system ID, interface, MAC, next hop type, VLAN, VN ID, VN type, VRF name, and state. States include expected, missing, and absent with color-coded indicators. Tooltip provides timestamp and time in state for a missing MAC address.

This information helps you determine when a MAC address disappeared, when it became inconsistent with EVPN expectations, and when normal operation resumed.

Network monitoring dashboard showing MAC address status over a 5-minute time series. Timeline highlights expected green and missing red states. Details panel displays system ID 5254003847B5, interface remote, MAC 020000000001, VLAN 46, VN ID 30010, VN Type vxlan, and VRF Name red.

The detailed view shows the exact state of the MAC address at each recorded timestamp. From this view, you can select a specific point in time and open the Snapshot view to investigate the network conditions that correspond to that state.

Snapshot view

The Snapshot view provides a point-in-time view of MAC address states. It shows the state of MAC addresses at a selected historical timestamp, helping you correlate MAC address behavior with network events.

The Snapshot view reports the following states:

  • Expected

  • Missing

The State column shows the MAC address state at the selected timestamp. A state of Missing indicates that the MAC address was expected but not present on the system at that point in time. A state of Expected indicates that the MAC address was present and operating normally.

The view below lets you analyze the historical state of all MAC addresses in the blueprint from a single table and determine how many MAC addresses were present or missing at the selected point in time.

MAC Address Table showing system IDs, interfaces, MAC addresses, VLANs, VN IDs, VRF names, states, and last update times. Highlights include missing states in red and expected states in green for network status. Filters applied for specific MAC range and VN ID 30010. Snapshot taken on 2026-08-14 16:35:01.

The view below can help identify network events that caused the MAC address to become unavailable.

MAC Address Table interface showing network details including MAC addresses, VLANs, VRFs, and snapshot timestamp. Missing data is indicated in a pink box. Page 1 of 6.

The view below indicates that the MAC address was present and expected at the selected timestamp, which can help confirm recovery from a previous network issue.

Network management interface showing a MAC Address Table with details including Snapshot Time 2026-08-14 16:40:00, System ID 5254003847B5, Interface remote, MAC Address 02:00:00:00:00:01, VLAN 46, VN ID 30010, VN Type vxlan, VRF Name red, and entry updated 12 minutes ago.