I would first suggest you to run a wireshark and filter for the ip address source or cflow packet in order to verify the incomming traffic hitting Orion Netflow service port (amount of packets) . Also i would recommend you to open a support ticket on this as well.
Do you see a category called unmonitored traffic in your graphs? If so, you may want to enable monitoring on all ports to make sure you are seeing those other ports (Settings-NTA Settings).
I grabbed a wireshark cap and it looks like data is being received. For example, I see 25Mbps on an interface but when I click it for details it only shows a few minor entries.
However, we are using netflow v5 but wireshark shows it as version 7. Does this have anything to do with nde?
Mav, there is unmonitored traffic but it is only a few kbytes compared to the tons of traffic I should be seeing.