Network Management

NTA - Netflow v5, v9, and IPFIX Wireshark packet capture

The information below describes how to read a Netflow v5 Wireshark capture. This can be useful when troubleshooting an issue where a customer is questioning the data being displayed in the charts. For example: Endpoints, Application port numbers and Endpoint conversations to name a few.

First published date

10/19/2018 6:16 PM

Last published date

9/3/2025 10:42 PM

Overview

This article shows how the NetFlow data looks like in the Wireshark™.

Product section

Netflow Traffic Analyzer

Resolution

  • Launch Wireshark from the SolarWinds server where the NetFlow collector is installed
  • Start the capture
  • Apply filter to capture only NetFlow data (see below example with CFLOW) and press 'Apply'



 

  • A couple of things to notice to easily find the NetFlow version being exported. To the far right of the flow packet the NetFlow version is displayed.  Flows are displayed as PDU.  Each PDU contains one conversation.

 



 

Expand the PDU to view the flow data included in each flow.

  • NetFlow v5 is not template based.
  • All required fields are always included in the flow data.
  • Either the InputInt or OutputInt field must contain a valid interface index value for the flow to be processed
  • Either the SrcPort or DstPort field must contain a valid application port number in order for the flow to be processed

 



 

Using a capture filter will only capture data for that specific device and will allow Wireshark™ to capture all flows that we need to investigate:


 

Note: Always save the capture as a PCAP.