Hi everyone,
I've run a netflow realtime report of the top 10 conversations happening on a particular interface. The result is strange. Of the top 10 conversations, I'm seeing only 3 combinations of source IP, source port, destination IP and destination port. I'll try to post the report below:
Based on this, I felt that conversations 1-4 should be one conversation with the total traffic and packets added up. It would then account for a higher % of the traffic. Conversation 5 as it's listed in the report, should be a seperate conversation because the destination port is different. conversations 6-10 should be added together because it is the same communication. Those last 4 together would be the new conversation #2 because conversation 5(as listed above) would be less megabyles than conversations 6-10 added together.
Is my netflow calculating wrong or am I not getting something?
Thanks,
Paul