Does NetFlow showing information of the flow without counting protocol headers?

Does NetFlow showing information of the flow without counting protocol headers?

Hello.

I would like to undenstand one point. I'm using NetFlow Analyzer Free edition. Not so much time ago I had a lot of traffic. It was a type of DoS attack where attacker sent me a lot of empty TCP Ack packets (packets without data. Only headers. And it was ack packets by RFC standart so there wasn't been resets of TCP sessions). At the NetFlow Analyzer I saw bandwith of the attack at the sum information of the interface bandwith, but when I tryed to figure out who it was I couldn't find any big data at the "conversation", "source" or "destinations" fileds of interface.

So, am I right that application is showing only data bytes from a flow (does application cut off protocol header number of bytes from each flow)?

Best Regards.

                New to ADSelfService Plus?