Abstract. Packet monitoring arguably needs the flexibility of open architectures and active networking. In earlier work we have implemented FLAME, an open monitoring system, that balanced flexibility and safety while attempting to achieve high performance by combining the use of a type-safe language, lightweight run-time checks, and fine-grained policy restrictions. We seek to understand the range of applications, workloads, and traffic, for which a safe, open, traffic monitoring architecture is practical. To that end, we investigated a number of applications built on top of FLAME. We use measurement data and analysis to predict the workload at which our system cannot keep up with incoming traffic. We report on our experience with these applications, and make several observations on the current state of open architecture applications.