Hi Guys,
I´m totally new to NTA and the orinon platfrom and question about how the same conversation is collected and presentet if there are multiple devices along the path that collect/send netflow data.
so basically I have this scenario:
|host| ---- |layer3 device| ----- |layer3 device| ---- |firewall| ----- |server|
all the devices are set up to send netflow data to the orion platform, and the interfaces are configured as ingress.
My question is how this will effect the presentation of the data, will I get 3 "copies" of the same flow and the sum of all the traffic passed through will be 3 times the actual traffic amount or will the platform somehow merge it and recognize that it is the same flow being reported by different devices?
The thing is that when I look at the detail for the flow I can see which devices reported and how much traffic that have been passed through the different interfaces. What I see Is a the different devices also report different numbers, so in this case it is not 3 copies of the same conversation,
Thanks in advance