The invention provides a network flow
analysis method, device, equipment and medium, and the method comprises the steps: analyzing a packet header of any data packet, and when the packet header of any data packet is analyzed to a tunnel encapsulation layer protocol, if the tunnel encapsulation layer protocol is a multi-protocol
label switching protocol, sending the packet header of any data packet to a network; the method comprises the following steps of: storing a first analysis result which comprises
metadata extracted from header information of each layer of protocol which is analyzed at present when a
label stack of a multi-protocol
label switching protocol is analyzed and a protocol type identifier which cannot be analyzed exists in a
current analysis position of the label stack of the multi-protocol
label switching protocol is identified, and then returning to an initial analysis position of the label stack so as to obtain a second analysis result which comprises
metadata extracted from header information of each layer of protocol which is analyzed at present; and determining a
target analysis protocol from the protocol feature
library, and performing analysis again from the initial analysis position to obtain a second analysis result, thereby determining a
stream analysis result based on the first analysis result, the second analysis result and third analysis results of the remaining protocols. According to the embodiment of the invention,
information loss in an analysis process can be avoided.