We are having an issue where random machines send a numerous data from one site to another on a specific port. We can defiantly identify those machines based on the traffic volume within an hour period using the sFlow sensor. The problem is that we have to actively monitoring the system by keeping an eye on it.
Is it possible to include the first top talker based on the traffic volume in a custom e-mail alert? So the alert will tell us that this machine is now exceeded x amount if GB for this hour.