NetFlow management
NetFlow Management options ensure that you are able see all flow data available from flow-enabled devices on your monitored network. On new installations, all the options are enabled by default.
Due to the volume of data involved in flow monitoring, you may find it necessary to disable the inclusive monitoring options to save database space.
Access the NetFlow Management options
-
In the SolarWinds Platform Web Console, click Settings > All Settings.
-
Under Product Specific Settings, click NTA Settings.
Options for NetFlow Management are available on top of the NetFlow Traffic Analyzer Settings page.
-
Click Save after modifying any options.
Available options
If selected, all flow-enabled devices in the SolarWinds Platform database sending flow data to the server hosting NTA are automatically added as NetFlow sources. All recognized NetFlow sources are listed under NetFlow Sources on NTA Summary.
If selected, NTA retains all flow data provided by NetFlow sources on your network, including flow data for ports that you are not actively monitoring.
A benefit of having this data is that, should you see a significant percentage of unmonitored traffic under Top XX Applications, you can expand the tree to drill down to the interface level. Click Monitor Port to track this traffic by port.
To save space in your database and discard data from unmonitored ports, clear this option.
This option may significantly increase the processing load on both your NTA server and your SolarWinds Platform database server.
If selected, NTA automatically monitors flow packets even if one of the involved interfaces is not managed by NPM.
If you want NTA to discard any flow packets where only one of the involved interfaces is managed by NPM, clear this option.
Clearing this option may significantly decrease the processing load on both your NTA server and your SolarWinds Platform database server, but it will also decrease the amount of flow data stored in your SolarWinds Platform database.
If selected, NTA automatically associates a flow with an appropriate NPM node if the node has multiple IP addresses and is sending flows from a non-primary address.
If this option is selected and an unknown traffic event occurs, NTA notifies you about it in the yellow banner below the main tool bar.
Enable this option for SolarWinds NTA to monitor interfaces for Wireless Controller nodes on the NetFlow sources widget and on the Manage sources page.
This option is enabled by default. Disable this option if you do not want to process and store IPv6 flow data. For more information, see IPv6 traffic processing in NTA.
This option must be enabled for Meraki MX firmware version 15.13 and earlier. Clear this option if you upgraded your devices to MX firmware 15.14 or later.
With NAT Stitching, you can observe conversations that traverse through Network Address Translation (NAT) devices, such as routers, security gateways, firewalls, and load balancers. For more information, see NAT Stitching.
Click this link to navigate to the Last 200 Unknown Traffic Events page. This page provides a list of traffic events involving flow data received from an unmanaged interface. You can use that page to add the relevant interface to NetFlow Sources. For more details, see Resolve Unknown Traffic.