Kentik has joined Infoblox! Read the blog post

August 2026 - Traffic

Prev Next

The following updates were released to the Kentik platform for Traffic during August 2026.

Features

  • Structured BGP alarm evidence: BGP alarm incidents now display structured evidence — affected prefixes, vantage points, flagged ASNs, and timing and impact details — in the incident log and alarm drawer, replacing raw legacy text.
  • Expanded AI platform traffic detection: OTT detection patterns for OpenAI, Anthropic Claude and Perplexity traffic were added and refined, improving AI-platform visibility in traffic classification.
  • New and updated OTT service detection: New detection was added for Ookla speedtest servers, Google Maps, Waymo, Fullstory, Glean, Infoblox SaaS and Infoblox Threat Defense, plus new OTT services (Infold Games, Arena Breakout, Native Instruments) and regional ISP patterns (Telia/Nordfibre, WilhelmTel, Sasktel). Several services were also reclassified into more accurate categories, including Proton, Microsoft Clarity, Bytedance Pangle and Pendo.io.
  • Faster query planning for large environments: Query planning now parallelizes device metadata lookups across up to eight concurrent shards by default instead of running serially, significantly speeding up planning for tenants with large device counts.
  • Plan max-FPS history: You can now retrieve a time series of a plan's maximum flows-per-second limit over time, showing when and how capacity limits changed.
  • Higher default sampling burst allowance: The default unused sampling quota (burst carryover) was raised from 0 to 30,000 FPS, so devices without a custom sampling configuration absorb traffic bursts better.

Bug Fixes

  • RPKI validation cache: RPKI-validated prefixes are no longer incorrectly marked Invalid because of a stale validation cache when a BGP route's origin AS changes.
  • sFlow sample count accuracy: sFlow counting now stops once the declared sample count is reached, so trailing garbage bytes in UDP datagrams no longer inflate flow counts.
  • Stale CDN patterns removed: About 197 obsolete OTT detection patterns tied to the decommissioned footprint.net CDN were removed and affected streaming services remapped to current domains, restoring accurate classification.
  • GitHub OTT traffic identification: GitHub's published IP and CIDR ranges were refreshed across the web, API, git, Pages, Packages and Codespaces categories.
  • ASN naming corrections: ASN name mappings were corrected and expanded, including misspelled Kakao Enterprise entries, Transtelco renamed to "Flo Networks (Transtelco)", and Starlink/SpaceX entries.
  • BGP dimension queries: Fixed query errors when using certain BGP routing and next-hop dimensions, such as source and destination route prefix length and next-hop IP and ASN, in Data Explorer.
  • Chart rendering with many dimensions: Fixed a chart rendering and query issue in Data Explorer when the auto-merge-series option was used with a high number of dimensions.
  • Traffic Breakdown widget tabs: Tab selection in the Traffic Breakdown dashboard widget is now consistent, so the correct tab stays selected.
  • Capacity plan crash: Capacity plan Detail pages no longer crash when interface utilization data is missing.
  • Country map data: 83 missing FIPS country codes were added to the map allowlist, fixing 404 errors on certain country views in Customer Traffic Overview.
  • Market Intelligence setup tasks for subtenants: Fixed a 404 error when loading Market Intelligence (MKP) setup tasks for subtenant users.
  • Array columns on legacy query endpoints: Array-typed columns such as numeric[] and timestamp[] on the /q and /v202211/query endpoints now render as proper array values instead of raw internal data, with correct NULL handling.
  • v202608/q response format: The /v202608/q endpoint now returns the documented row-object format instead of row-array format.
  • Streaming query error codes: Certain user query errors on the streaming query path now return HTTP 400 instead of HTTP 500.
  • sum() on large counters: Queries summing large uint64 metric columns no longer fail when the total exceeds the signed 64-bit range.
  • BGP listener protocol guard: BGP listener sockets are no longer created as Multipath TCP, avoiding MD5 authentication incompatibility and spurious detections in network monitoring tools.
  • Traffic widget data for Ixia IBP100: Ixia IBP100 devices now report bit-rate metrics, so the Traffic widget is no longer empty for them.