Minimum required NetFlow fields

Document ID : KB000021617
Last Modified Date : 14/02/2018
Show Technical Document Details

Question:

What is the minimum required fields and requirements, in order for Harvester to process NetFlow.

 

Answer:

1. These are the minimum required fields for data to appear in RA/NFA:

        One of the following:
            1   - IN_BYTES or 85 - IN_PERMANENT_BYTES (NFA only)  
                   *NOTE: For ASA devices we need both 231 - FW_INITIATOR_OCTETS, and 232 - FW_RESPONDER_OCTETS
 
        and the rest:
            4   - PROTOCOL
            7   - L4_SRC_PORT
            8   - IPV4_SRC_ADDR
            10 - INPUT_SNMP
            11 - L4_DST_PORT
            12 - IPV4_DST_ADDR
            14 - OUTPUT_SNMP
 
 
2. The other question is how much data we are receiving from these interfaces:
 
        The minimum limits for interface data to be included in reports are 50 KB for protocols, and 100 KB for hosts or conversations per 15 mins.