I recently downloaded the trial of NFA5 and set it up to recieve netflow data from our core switch (6509/sup720). I setup IP groups for all of our subnet's so that i could monitor traffic coming in/out of our remote sites. The interface names that show up on NFA do not appear to correlate to vlans/interfaces, but by monitoring individual interfaces I have been kind of able to tell which is which.
I want to mainly see the traffic destined for the Internet from these sites. However there is some extraneous traffic that isnt internet traffic on the interface which appears to have most of the netflow data for internet traffic. I have noticed that with the custom reports you can restrict between source/destination network, however I want to restrict for example between the source network of 10.1.x.x and anything that is not 10.x.x.x. I havent been able to find a way (if its possible) to do the NOT 10.x.x.x portion. Any ideas?