Wrong timestamp of the flow
Timestamp of the flow is in the past or the future.
|Question/Problem Description:||In advanced analysis are flows that differ with the selected time interval.|
|Steps to Reproduce:|
Incorrect timestamps usually occur if the flow source is a third-party device. Relative timestamps are sent in netflow v9 or IPFIX if there is missing SysUptime information or this value is incorrect.
1. Create packet capture by tcpdump, eg:
2. Calculate the timestamp of the flow and compare this value in the advanced analysis.