MetricSplit › Guides › How bandwidth is measured

How is bandwidth measured on a network (and why averages mislead)

Bandwidth use is measured in bits per second: the number of bits that crossed a link in a period, divided by the length of the period. Everything else, and every disagreement between two tools, comes from how long that period is, which direction is counted, and which moments are used.

Bits, bytes and the period

Routers count bytes. Multiply by 8 for bits, divide by the number of seconds in the period, and you have the rate: 3.75 GB in 5 minutes is 3.75 × 8,000 megabits ÷ 300 seconds = 100 Mbps. Link speeds are quoted in bits (Mbps), storage in bytes (MB, GB): mixing the two is the most common factor-of-8 mistake.

Why the averaging period matters

Every measurement is an average over its period. The longer the period, the more it smooths away the moments when the link was full. Take one link on a working day:

Averaged overReadingWhat it tells you
5 minutes, busiest of the afternoon94%Users were waiting.
1 hour, that afternoon71%Looks busy but fine.
24 hours28%Looks mostly empty.

All three are correct, and only the first describes what users felt. A daily average includes the night, when the link is idle, so it is almost always low. This is why a link can be "28% used" and still be the cause of complaints.

Peaks overstate, averages understate

The single highest reading of the week overstates the need: it might be one backup or one large download. A long average understates it. The usual middle ground is a percentile: the 95th percentile of 5-minute readings is the value that 95% of the readings are at or below. It ignores the few highest moments and still reflects the busy hours. Many providers bill on the same idea.

Count each direction

Download (into the site) and upload (out of the site) are measured separately, and a link can be full in one direction and idle in the other. Adding them together, or quoting only the larger total, hides which direction is the bottleneck. Compare each direction with its own capacity.

Count the hours that matter

For an office site, the hours that matter are its business hours, in its own time zone. Including nights and weekends lowers every figure. A 24-hour site is the exception: every hour counts.

Counters or flow records

Interface counters (usually read over SNMP) give you the volume per direction. Flow records (NetFlow v9 or IPFIX) give you the volume and what it was: application, host, direction and interface. Sampled flow exports (1 packet in N) need the sampling rate to scale the counts back up.

How MetricSplit measures

5-minute readings from flow records, per direction, in each site's own business hours. A circuit's state is set by the 95th percentile of the last 7 days: over 85% needs action, 60 to 85% is approaching. You always see how much data a figure rests on.

Book a free assessment