I have a cisco router connected to a T1 with some users behind it. Every now and then someone is downloading something during an inconvenient time and using up all the bandwidth. I am trying to use netflow analyzer to determine which IP address is requesting the download.
However its giving me inconsistent data (see picture). This picture is the OUTBOUND traffic of our INTERNAL interface fa0/1. It clearly says in the lower right the outbound traffic is 1.44mbps, however when you look at the top 4 "endpoints" in the traffic column it says they have only downloaded 69.7KB, 63.6KB, 26.7KB, and 26.3KB respectively. This was after the monitor had been running for close to a minute. During that time the person downloading should have been able to get up to 60mb of data, clearly not reflected in the chart.
Furthermore when I test this with myself as the downloader and I KNOW I am the only person using up the 99% of the T1 pipe, it fails to register on this chart, even though it does say the corrrect traffic utilization in the lower right.
Can anyone help with this?