1 of 1 people found this helpful
If you take a wireshark capture on the Orion server and filter for sflow traffic from this device this may help understand it a bit better.
Take a look at the InputInt and OutputInt values - these are the ingress/egress interface indexes.
Both interfaces will be shown under netflow sources, regardless of whether they are configured to forward flows or not. Most likely, conversations are coming into/going out of your configured interfaces and out of/into the other ones.
This should be normal behavior.