We have a fairly large environment. When you specify a flow through example a Ten Gigabit connection. I want to view all traffic comunicating on port 22 through that connection. The dash board only shows top 5 talkers. Is there anyway to have the dash board be able to have an expanded view of smaller talkers than just the top 5.
Another example would be a user is complaining that they are having issues connecting to a sql server, but we need to identify their station traffic specifically. Their traffic in the grand scheme of others on that specific switch does not grant top 5 status. No other user has the same complaint and the sql server is fine. In our department we have a lot of finger pointing going on. That user would for example be viewing a movie or has a rogue application pegging ther pcs pipe. Netflow could allow us to narrow down that his PC is the real issue. Netflow could save us a lot of time of the game of passing the buck so to speak How could I tune NTA to allow for a more granular switch port view. I do have IP flow configured on all of our user and data switches on all static endpoints.
Thanks in advance,