    Does Realtime Netflow Analyzer aggregate flows?


      I am trying to better understand how to interpret data from realtime Netflow Analyzer's conversation window. I notice often I have several flows shown with same source and destination IPs and ports. So it seems to me they are the same flow but maybe each one was exported when the timer was timed out. If so, is it true Realtime Netflow Analyzer does not aggregate the flow data that belong to the same connection? I am reading Cisco's Introduction to NetFlow document and it says "netflow collector can combine and aggregate traffic."

      Data are exported from Cisco 1811 router and no matter what values I set for timeout, I pretty much always see the symptoms above on regular basis.