Observability

New Device Not Appearing as a NetFlow Source in NTA

First published date

3/2/2026 6:35 PM

Last published date

3/2/2026 6:35 PM

Overview

A newly added network device may not appear as a NetFlow source in Network Traffic Analyzer (NTA) even though SNMP connectivity is successful. In such cases, NetFlow traffic may not be visible, or the device may be missing from NetFlow source lists.

Product section

Hybrid Cloud Observability

Resolution

Confirm NPM Monitoring Requirement:

  • Each device exporting NetFlow to NTA must be monitored in NPM.

  • Only nodes whose interfaces are discovered and successfully polled by NPM can be added as NetFlow sources in NTA.

  • If a device exports NetFlow data but is not monitored in NPM, the traffic appears only as aggregate traffic from unmonitored devices.

  • In this state, NTA cannot associate flows with specific interfaces or devices.

  • Add the device to NPM and ensure SNMP polling is successful.

  • Verify that the device interfaces are properly discovered and visible in NPM.

  • Reference: Set up network devices to export NetFlow data 

    Configure NetFlow Export on the Device

    • After confirming NPM monitoring, configure the device to export NetFlow data to the NTA collector.

    • Ensure the correct collector IP address and NetFlow port (for example, UDP 2055) are used.

    • Reference: Verify Netflow traffic is received in NTA port 2055 

Verify Flow Source Registration

  • Navigate to Settings > All Settings > NetFlow Settings > Flow Source Management.

  • Image_2025-12-30_17-56-06.png
  • Check whether the device appears as a NetFlow source.

  • If listed, confirm that flows are actively being received.

 

Validate NetFlow Packet Reception

  • If the device does not appear in Flow Source Management, perform a packet capture on the NTA server using Wireshark to verify NetFlow traffic is arriving at the configured port.

  • If Wireshark installation is not permitted, use supported alternative verification methods available through SolarWinds utilities or THWACK guidance.

I cannot install wireshark on my server. Is there any alternative method I can use? - THWACK

Please note that Thwack is a community space where users may post any content as a suggestion or recommendations to you for your internal use. The information set forth herein may come from third-party websites or customers. SolarWinds is not liable for any downtime or any issue that may occur if you perform the following suggestions on the link provided. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.