I'm getting high usage of unknown application from NBAR. From Netflow application, the only high bandwidth usage is microsoft-ds, so can I assumed that the unknown reported by NBAR is windows application. If it's correct, why is NBAR not able to identified microsoft applications or it is because Cisco's PDLMs is not able to identify. FYI, I'm running Netflow Analyzer Pro.6.1 and report also attached