Network Management

Resolve malformed flow data warning in NTA

The article provides steps for resolving malformed flow data that are being dropped, leading to inconsistencies between the amount of data reported by NPM and NTA.

First published date

6/4/2024 12:58 PM

Last published date

6/3/2025 11:10 PM

Overview

NTA can detect malformed data based on a high number of octets, packets, or out of range MTU size. Malformed flow data are then dropped. If the amount of dropped data is higher, it may lead to inconsistencies between the amount of data reported by NPM (SNMP polling) and NTA (NetFlow).

Product section

Netflow Traffic Analyzer

Cause

Malformed flow data that are dropped due to high number of octets, packets, or out of range MTU size detected by NTA.

Resolution

The warning is triggered every 24 hours. If you don’t see the event every day for a particular device and the amount of dropped PDU is low, most likely no action is needed. Few drops may occur shortly after the device firmware update or when the NetFlow template changes for any reason.

When the malformed flow dropped warning is triggered every day for a particular device, or the amount of dropped PDU is high, follow the steps below to resolve the issue.
  1. Restart the device.
  2. Make sure you are using the latest version of Hybrid Cloud Observability.
  3. Review the device configuration.
  4. Make sure your device is running on the latest firmware. If there are bugfixes related to NetFlow or IPFIX, upgrading to the latest firmware may help resolve the issue.
  5. If none of the above steps resolve the issue, open a helpdesk ticket.