We use an ISP to handle our WAN infrastructure. This means that we manage only the switches (usually layer 2...Cisco 2960) at remote sites and the ISP owns the routers. We have read-only SNMP access to the ISP's routers...the ISP's routers are NOT configured to do Netflow. All WAN traffic goes to two head-end routers. At our 6500 switch interfaces which connect to these head-end routers, I enabled Netflow v5...both directions. I see some Netflow traffic and I get Top X type reports, but that is not what I want. When a person at WAN site Y complains of slow network response, I want to be able to see what is happening on that subnet...today, yesterday, a few days ago. Is someone streaming radio or video over a slow connection? Is it legit traffic like SMB or Exchange?
How can I get these reports or real-time data?