The IPS/IDS is reporting a flood of DNS requests coming from the SolarWinds server which I realize is associated with NetFlow. The volume is such that it actually puts a certain amount of stress on the IPS/IDS appliance although it doesn't appear to be service affecting. Curiously the event starts at exactly the same time every 48 hours and runs for 2 to 2 and half hours. Apparently this is a scheduled activity so does anyone know how to implement a change to the schedule?