Forum Discussion
Open source gets this done far better and more elegantly. NFsen, for example, allows you to define a tcpdump-style filter for flow selection. Very powerful and very useful and this should be added to LM ASAP (advanced feature option off by default if needed). Things have improved with NetFlow LM the past few years, but it is still very primitive and lacks even basic alerting tied to searches. The feature seems to be stuck where it is -- would be great if someone at LM could show us a roadmap...
FWIW, I have been working on a way to extract NetFlow data via the API to workaround this. It is possible, but not trivial. This should be within the main UI.
Also, add IPv6 support -- we get the weirdest results from our SonicWall that sends both IPv4 and IPv6 flows :).