Home Solutions Gigamon
GigaVUE · AMI · ThreatINSIGHT · Cloud Suite
Gigamon logo

You can’t protect
what you can’t see.

Gigamon is a Deep Observability Pipeline that sits between your network and your tools. SOC, NetOps and cloud teams all get traffic data from one source. Gigamon collects traffic from physical, virtual and cloud segments, adds L7 metadata and sends it to SIEM, NDR, IDS and packet-based tools.

4,000+
organizations worldwide use Gigamon, including banks, telecom operators and the public sector.
81 %
of Fortune 100 companies are Gigamon customers (according to Gigamon).
2004
year founded. One of the pioneers of packet brokers and observability.
L1–L7
from the physical TAP to application metadata.
Deep Observability Pipeline

One pipeline between the network and your tools.

Gigamon collects traffic from any segment, processes it at L1-L7 and sends each tool the data in the format it needs. Nothing is lost or duplicated, and there are no blind spots.

01 · ACQUIRE
TAP / SPAN / vTAP / UCT
Physical TAPs, switch SPAN ports, vTAPs in hypervisors, UCT agents in Kubernetes.
02 · AGGREGATE
GigaVUE Visibility Fabric
Aggregation from dozens of sources, filtering by session, port, VLAN, MPLS and VXLAN.
03 · TRANSFORM
GigaSMART · AMI
SSL decryption, de-duplication, slicing, masking and generation of application metadata.
04 · DELIVER
42+ tools
SIEM (Splunk, Sentinel), NDR, IDS, NPM, recorders, forensics: each gets its own stream.
70 %
reduction in SIEM data volume thanks to de-duplication and filtering.
10×
more visibility into east-west traffic compared with ordinary SPAN.
100GbE
line-rate processing on the GigaVUE HC3/HC1 series and line-rate AMI on the TA series.
Product family

GigaVUE runs on hardware and in the cloud.

Visibility Fabric

GigaVUE HC-Series

Modular HC1/HC3 chassis for the data center. Support for 1G/10G/40G/100G, line-rate aggregation and filtering, hot-swap GigaSMART modules.

HC1 · HC1-Plus · HC3 Series-3
High-density TA

GigaVUE TA-Series

1RU “traffic aggregators”: TA25, TA40 and TA100 with 32×100G and inline filtering. Built for large data centers and telecom operators.

TA25E · TA200 · TA400
Cloud

GigaVUE Cloud Suite

Visibility in AWS (VPC Mirror), Azure (vTAP), GCP, OpenShift and Kubernetes. The same metadata as on-prem and a single FM console.

AWS · Azure · GCP · K8s · OpenShift
Smart processing

GigaSMART

Service functions: SSL/TLS decryption (including TLS 1.3), de-duplication, slicing, masking, NetFlow generation, header stripping.

SSL 1.3 · DTLS · CAS
L7 Metadata

Application Intelligence (AMI)

7,000+ application-layer metadata attributes: DNS queries, HTTP headers, TLS fingerprints (JA3/JA4), SMB usernames, SQL queries, delivered to the SIEM in structured form.

5500+ apps · 7000+ attrs
NDR / Threat Intel

ThreatINSIGHT

A cloud NDR service built on AMI streams. It detects C2, lateral movement, data exfiltration and ransomware behavior, and analyzes behavior anomalies.

SaaS · ATI · MITRE ATT&CK
Use cases in Uzbekistan

Where Gigamon removes blind spots.

East-west traffic in the data center

SPAN ports can’t handle server-to-server traffic. The GigaVUE TA series collects all east-west traffic and delivers it to the SOC.

Encrypted traffic (TLS 1.3)

GigaSMART decrypts SSL once and sends the decrypted stream to NDR, IDS and DLP, so each tool doesn’t have to decrypt it.

Visibility in AWS / Azure

VPC Mirror, vTAPs in EC2 and Azure VMs, container support. The SOC sees cloud traffic the same way as local traffic.

Lower load on the SIEM

De-duplication and AMI replace raw payload. SIEM data volume drops by 50-70%, you spend less on licenses and SQL searches run faster.

Forensics and compliance

Full pcap goes to a network recorder and is kept for 30-90 days. This meets Central Bank, government and PCI DSS requirements.

NDR from a single source

ThreatINSIGHT or a third-party NDR (LiveAction, Vectra, Darktrace) receives a single metadata stream, with no duplicate infrastructure.

CYBER BOOST × Gigamon

Visibility fabric design and SOC integration.

We design the GigaVUE fabric for your network architecture, configure GigaSMART cards, set up filtering rules and integrate with your SIEM/NDR. We supply the hardware based on the feasibility study.

3-6 weeks
typical time from the feasibility study to production traffic in the visibility fabric.
PoC
a 4-week pilot on part of the traffic with real SIEM/NDR integrations.
RU/UZ
certified GigaVUE Design and GigaSMART engineers.
L1–L3
local support and a spare parts warehouse in Tashkent.
FAQ

Frequently asked questions about Gigamon.

What is a Deep Observability Pipeline?
A Deep Observability Pipeline is a layer between the network and security tools. Gigamon collects traffic from physical, virtual and cloud segments. It processes the traffic (de-duplication, SSL decryption, application metadata) and sends it to the right tools: SIEM, NDR, NPM, IDS, packet brokers. Each tool gets only what it needs and is not overloaded.
How is GigaVUE different from an ordinary SPAN port?
SPAN ports are limited in number and bandwidth. They duplicate packets and drop them under load. The GigaVUE Visibility Fabric collects traffic from dozens of TAPs and SPAN ports. It filters the traffic, removes duplicates, decrypts SSL and sends a copy to each tool at line rate, without loss.
What is Application Metadata Intelligence (AMI)?
AMI extracts 7,000+ application-layer attributes from traffic (DNS queries, JA3 fingerprints, HTTP headers, TLS metadata, usernames in SMB/Kerberos and so on). It sends them to the SIEM/NDR as structured events. This gives you L7 visibility without storing the payload.
Does Gigamon work with the public cloud?
Yes. GigaVUE Cloud Suite runs in AWS, Azure, GCP, OpenShift and Kubernetes. It supports VPC Mirroring (AWS) and vTAPs in virtual machines and containers. You get the same metadata and the same visibility fabric as in the data center.
Why do you need a packet broker if you have a SIEM?
A SIEM works with logs, but 80% of threats are visible only in network traffic. A packet broker (GigaVUE) turns “raw” traffic into structured events and packet flows for SIEM, NDR, IDS and forensics. This removes blind spots, especially for east-west traffic and encrypted communications.
Request · Gigamon

A visibility PoC in 4 weeks.

Tell us what you need: east-west visibility, data for your SIEM, NDR, SSL decryption or cloud visibility. We will prepare a design and a specification.