On 2014-06-02, Andy <a...@brandwatch.com> wrote: > I think you might have to try softflowd instead of the built-in sflowd.. > > These guys had the same problem and moved to softflowd to allow them to > analyse DDOS traffic with netflow.. > > https://ripe68.ripe.net/presentations/276-DDoS.pdf
see also the video from UKNOF28, though my understanding was that a big part of the reason for softflowd was to capture stats from blocked packets.