Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

netflow statistics

I'm trying to understand what netflow statistics are being show when using sh ip flow top and the sh ip flow top (#) aggregate commands. What I'm looking for is a real-time picture of statistics, not a n accumulation of stats. We have periods of congestion and an alert system setup to notify me when that congestion takes place. I'd like to connect to the router where the congestion is occurring and get a snapshot of the top ten talkers at that moment. However I'm unsure if that is a real time picture or an accumulation of statistics since either the last clear counters or clear ip flow stats command was issued. Can anyone offer some clarity on how netflow's stats are presented?

Thank you,

Bill

1 ACCEPTED SOLUTION

Accepted Solutions
New Member

Re: netflow statistics

Bill,

The "show ip flow top" scans the netflow cache in real time and shows you a snapshot of what's happening in your router at this exact moment.

Aggregation is of the traffic that's in the netflow cache right now; and isn't related in any way to the last clear command.

So when you see congestion, you can be 100% confident that the "sh ip flow top ... " output shows you exactly what the cause is.

2 REPLIES
Bronze

Re: netflow statistics

Using show ip flow top-talkers and match criteria command can be used to display statistics for unaggregated top flows

Using the show ip flow top-talkers command to display the aggregated statistics from the flows on a router for the highest volume applications and protocols in your network helps you identify, and classify, security problems such as a denial of service (DoS) attacks because DoS attack traffic almost always show up as one of the highest volume protocols in your network when a DoS attack is in progress. Displaying the aggregated statistics from the flows on a router is also useful for traffic engineering, diagnostics and troubleshooting.

New Member

Re: netflow statistics

Bill,

The "show ip flow top" scans the netflow cache in real time and shows you a snapshot of what's happening in your router at this exact moment.

Aggregation is of the traffic that's in the netflow cache right now; and isn't related in any way to the last clear command.

So when you see congestion, you can be 100% confident that the "sh ip flow top ... " output shows you exactly what the cause is.

361
Views
0
Helpful
2
Replies
CreatePlease to create content