http://www.cisco.com/en/US/technologies/tk648/tk362/technologies_white_paper09186a00800a3db9.html
NetFlow Version 9 Packet Header Format: Version: The version of NetFlow records exported in this packet; for Version 9, this value is 0x0009 Count: Number of FlowSet records (both template and data) contained within this packet System Uptime: Time in milliseconds since this device was first booted UNIX Seconds: Seconds since 0000 Coordinated Universal Time (UTC) 1970 ..... Regards Andrew On Tue, Feb 18, 2014 at 8:14 AM, Joe Loiacono <[email protected]> wrote: > > "cisco-nsp" <[email protected]> wrote on 02/17/2014 > 12:26:38 PM: > > > > The netflow exports stayed on local time. > > > > Are you sure it isn't an artifact of your collection/analysis > > software ignoring the flow start/flow end fields in the telemetry export? > > [sorry - looks like earlier reply didn't make it] > > I'm looking right at the packets. It's v5. Documentation seems to indicate > flow times are based on system uptime, which wouldn't change with a 'set > clock'. Tried turning off export and 'no ip flow-cache' for each interface, > but that didn't work. Would hate to reload ... > > Joe > _______________________________________________ > cisco-nsp mailing list [email protected] > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
