    NetFlow - theory and practice


      I am rather new to network security and NetFlow in general. Does anyone know of any technical references that I can read and study to introduce me to the forensic use of NetFlow data (esp. as presented by SW NetFlow)?

      Thanks for the help.

      By the way, what actually is an endpoint? Can it bew either internal or external?