Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Netflow data - How often is it exported to a collector and..

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Netflow data - How often is it exported to a collector and..

L1 Bithead

Our firewall is setup to export Netflow data to Nagios Network Analyzer.  We need to know:

 

a)  How often is data exported from the Palo Alto to the NNA collector, and

b)  How large are the packets sent from the Palo to the collector

 

Any ideas on where to find this information?

7 REPLIES 7

L5 Sessionator

The frequency of the net flow export can be configured by "Active Timeout" under the netflow profile.

 

Active Timeout is the frequency in minutes at which the firewall exports records (default is 5).

 

Check the following document:

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Netflow-Server-Profile-...

L5 Sessionator

check the following admin guide for more information. In the PDF search for "NetFlow Monitoring"

 

https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os.html

 

 

Sweet thanks for that!!  When I first read that before posting it sounded like the Active Timeout was what I was looking for.  As for the size of the netflow data sent at the Active Timeout interval, is that the setting of "Packets" under "Template Refresh Rate?"

Template Refresh Rate is different then the packet size. You can do pacps on the firewall to check the packet size.

 

Hope this helps.

So when the Palo sends the data to the collector every minute, it's just a single packet?

Not sure about the size it may vary. Firewall may send multiple packets. Check the screenshot i have attached. The screenshot is from a firewall sending the netflow packets to netflow server.

NetFlow.png

We can use the following command for some statististics:

 

 debug log-receiver netflow statistics

  • 3715 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!