Ask the Community
Groups
How to view NetFlow in WireShark - Connect IT Community | Kaseya
<main> <article class="userContent"> <p>Open the packet capture file (.pcap format) in Wireshark</p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/ITEVBKHSV05I/udp-png.png" alt="udp.PNG" class="embedImage-img importedEmbed-img"></img></p> <p> </p> <p>Select menu option Analyze->Decode As:</p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/ECMWG8LQYA87/decode-png.png" alt="decode.PNG" class="embedImage-img importedEmbed-img"></img></p> <p>Select '+' in lower left corner to add an entry to the 'Decode As' window</p> <p> </p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/3N14MX559RXG/decode-as-png.png" alt="decode_as.PNG" class="embedImage-img importedEmbed-img"></img></p> <p> </p> <p>Select 'none' in the 'current' column then choose 'cflow' from the list:</p> <p> </p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/G84QL2BPY5LW/cflow-png.png" alt="cflow.PNG" class="embedImage-img importedEmbed-img"></img></p> <p>Select 'OK' to save the selection. Note flow packets are subsequently denoted as CFLOW in the protocol column:</p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/2LZZG45OJQBU/flow-packets-png.png" alt="flow_packets.PNG" class="embedImage-img importedEmbed-img"></img></p> <p>Here is an example of a NetFlow v9 template:</p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/XG0BAU9Y86LJ/template-only-png.png" alt="template_only.PNG" class="embedImage-img importedEmbed-img"></img></p> <p>This is an example of NetFlow v9 flow records:</p> <p><img src="https://us.v-cdn.net/6032361/uploads/migrated/V3NU4ZXPQZXI/inkedv9-flowset-li.jpg" alt="Inkedv9_flowset_LI.jpg" class="embedImage-img importedEmbed-img"></img></p> </article> </main>