Flow records power the Network → Flows views — flow volume, traffic by category, top sources and destinations — and give the Ntuition Engine its richest "what changed" signal.

Gateway listeners

Each gateway listens for flow export on two UDP ports (defaults shown; change them under the gateway's Configuration tab):

Protocol Default port
NetFlow v5/v9 and IPFIX UDP 2055
sFlow UDP 6343

Settings follow a Global → Cluster → Gateway hierarchy: edit once and choose Save as Global Default, Save for Cluster, or Save for This Gateway. The panel lets you Preview YAML (validated against the collector before it's accepted) and then Apply, which restarts the gateway collector with the new pipeline.

Configure your devices

On each router or switch, configure flow export toward the gateway (or cluster VIP) for its site. The easiest path: open Settings → Sites, find the subnet, and copy the vendor-specific exporter snippet — snippets are pre-filled with the correct gateway address and port for Extreme EXOS, Extreme VOSS, Cisco, and Juniper gear.

General guidance:

  • WAN edge and branch routers → NetFlow or IPFIX (full accounting).
  • Data-center and campus switches → sFlow (sampled, negligible device overhead).
  • Mixed estates can export both; records are normalized into one stream.

Verify

Within a few minutes of device configuration, Network → Flows should show volume for the site. Use the protocol filter (TCP/UDP/ICMP) and Traffic by Category to sanity-check that classification looks right. If nothing arrives:

  1. Confirm the device is exporting to the right IP and port (VIP if clustered).
  2. Check for ACLs/firewalls blocking UDP 2055/6343 toward the gateway.
  3. On the gateway's Configuration tab, re-check that the flow receiver is enabled at the effective scope.

Retention note

Flow rows are kept 14 days at full fidelity by default (see Managing Data Retention to adjust), while 5-minute rollups preserve long-term trending.