I have two datacenters and one office. Im checking netflow for the traffic from my office.. I show port 80 from one IP 10.1.84.185 just trucking tons of data.. it was an IP from one of the users, I checked there system.. they didnt have anything as far as network bandwidth used.. and they turned off there system... but I still show data going on right now from that IP... how is that possible. the NETflow is v5 on a cisco 4500 switch.
I also check the destination IP 152.163.13.6 on the firewall.. little to no traffic to it..and the paloalto firewall monitor is a great tool.

