What is this?

This knowledgebase contains questions and answers about PRTG Network Monitor and network monitoring in general.

Learn more

PRTG Network Monitor

Intuitive to Use. Easy to manage.
More than 500,000 users rely on Paessler PRTG every day. Find out how you can reduce cost, increase QoS and ease planning, as well.

Free Download

Top Tags

View all Tags

How do i deal with the spiking that Netflow 9 creates?



from https://www.paessler.com/knowledgebase/en/topic/1423-how-to-monitor-cisco-asa-firewalls-using-netflow-9-and-prtg :

"If a connection is active for minutes or hours, the ASA sends one NetFlow packet with the total of the connection. This causes peaks in PRTG's graphs. "

I can configure the sensor channel to omit the spikes, but then wouldn't the overall measurement be wrong?

asa netflow-v9 spikes

Created on Nov 23, 2010 9:28:08 PM

3 Replies



filtering the spikes would make no sense because you would loose data.

Its simply the nature of the ASA Netflow that makes collecting the data difficult.

Netflow on the ASA was never meant to support traffic analysis.

Created on Nov 24, 2010 7:35:53 PM by  Aurelio Lombardi [Paessler Support]



Does this apply to ASR's as well? I see the same spiking behavior so I am guessing so.

Created on Nov 24, 2010 7:37:48 PM



we do not have a ASR for testing, sorry.

such a router is way too over sized for our own network.

Created on Nov 24, 2010 8:54:39 PM by  Aurelio Lombardi [Paessler Support]

Disclaimer: The information in the Paessler Knowledge Base comes without warranty of any kind. Use at your own risk. Before applying any instructions please exercise proper system administrator housekeeping. You must make sure that a proper backup of all your data is available.