3 Replies Latest reply on Jul 1, 2008 2:41 PM by Andy McBride

    NetFlow Data on DHCP address scopes.

      I did a little searching and did not really find the answer, so if this has already been covered I appologize.


      When I am looking at the netflow data and it shows a DNS name, is that name from the time of the event? or is that from the last lookup?


       My issue is this, I have a conversation showing very high data transfer rates between a server and a client machine on a DHCP scope associated with our VPN. How can I know that the DNS name it shows is accurate to the time of the event and not a cached entry or a current entry? it seems to me that the data becomes a lot less definitive without this, not meaningless, but you can't really count on the name associated with it if it's going to be dynamic depending on when the last lookup happend.