cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
161
Views
0
Helpful
0
Replies
Highlighted
Beginner

Stealthwatch Enterprise - Flow matching issues

Hi Guys

 

We've got Stealthwatch Enterprise up and running and so far I have to say I'm really liking it but we are having some issues with flow matching which results in a lot of traffic being picked up as being a new flow instead of being part of normal client -> server patterns.

 

We've 3 exporters at present all sending Netflow v9 format (Core router, Core firewall & Perimeter firewall) averaging about 1.5k fps. 

 

Has anyone recommendations on optimising this or encountered similar issues? Our flow record setup is as below

flow record StealthwatchFCNFRec
match ipv4 tos
match ipv4 protocol
match ipv4 source address
match ipv4 destination address
match transport source-port
match transport destination-port
match interface input
collect interface output
collect counter bytes long
collect counter packets long
collect timestamp sys-uptime first
collect timestamp sys-uptime last

 

Thanks Guys!