I setup an IP group for our ftp site to track traffic. I know from logs that today we've moved 700mb out via ftp connection, however the IP Group shows it as TCP_App, with a very small amount of traffic flagged as FTP.
I would like to see what port Netflow is seeing and flagging as unassigned which labels it TCP_App so I can put that into the FTP protocol listing.
Anyone have suggestions? All i see when clicking TCP_App is *