The traffic sensor discovers assets from the network traffic they already generate, revealing devices that active scanning never reaches.
Open beta
The traffic sensor is currently in open beta. Some features and requirements may still change as we refine the product.
What the traffic sensor does
Active scanning finds devices that respond to it. The traffic sensor finds the rest. It watches the traffic already moving across your network and discovers every device that communicates, including the ones scanning misses. The result is total visibility into what's on your network and how it all connects.
The traffic sensor is an extension of Network Discovery. It listens passively, so it adds visibility without adding load to the devices it discovers.
How it works
The traffic sensor is a passive, receive-only software component that runs on your own infrastructure. It reads a copy of your network traffic that you forward to it through one of these methods:
- SPAN or RSPAN/ERSPAN port mirroring
- A network TAP
- A packet broker
The sensor never injects, alters, or forwards production traffic. Its only outbound activity is throttled lookups against your own DNS servers, used to identify devices.
From the traffic it sees, the sensor records connection metadata: which devices are talking, on which ports, in which direction, and how much. It forwards that metadata to your Lansweeper site, where it appears in your inventory.
For supported operating systems and forwarding methods, see Traffic sensor requirements and Set up traffic collection.
What you can see
Where you place a sensor decides what it reveals:
- Internal asset coverage: Discover devices communicating across your network that active scanning hasn't reached.
For recommended placements and configuration per scenario, see Set up traffic collection.
Keep your inventory clean
Passive discovery can surface assets you don't want to keep long-term, such as devices that appear briefly and never return. Asset cleanup rules can set these assets to non-active or delete them automatically, so your inventory reflects what's actually on your network.
Configure these rules under Assets > Settings. For the full list of rules and what each one does, see Manage asset cleanup rules.
You can also remove unwanted assets using Flow builder. The BETA - Remove traffic sensor assets by filter workflow checks assets discovered by the traffic sensor against a comma-separated list of IP addresses you maintain, and removes any that match. It runs hourly by default, so your inventory stays free of devices at the addresses you've listed.
Privacy by design
The traffic sensor captures metadata needed to identify assets and characterize the connections between them. If you don't install it, no network traffic data is captured, transmitted, or stored by Lansweeper.
What the sensor sees
- IP and MAC addresses observed on the network
- Source and destination IPs and ports of observed connections
- The date and time of each connection
- Device identifiers, so observations link to the right asset
What the sensor does not see
The sensor never sees the content of your traffic.
In encrypted traffic, which is the vast majority of modern network communication, Lansweeper does not capture, transmit, or store TLS payloads, HTTPS request bodies, URL paths behind a domain, query strings, prompts, file contents, passwords, or chat messages. Anything inside encrypted tunnels stays private, and anything on segments you don't mirror is invisible to the sensor.
Where the data lives
Connection metadata is forwarded over TLS 1.2 or higher from your on-premises Network Discovery Hub to your Lansweeper Cloud site, hosted on AWS in the region you select (EU or US). Traffic data follows your asset-data retention policy and is fully deleted within 60 days of contract termination.
You stay in control
You control what the sensor sees and whether it runs at all. You decide which network segments are mirrored, and your administrators can disable the sensor at any time, which immediately stops new data from reaching Lansweeper.
In data protection terms, you are the Data Controller and Lansweeper is the Data Processor.
Get started
- Check Traffic sensor requirements.
- Set up traffic collection on your network.
- Install the traffic sensor.
If something isn't working, see Troubleshoot the traffic sensor and Gather logs for support.