interface GigabitEthernet0/1 ip flow ingress ip flow egress flow exporter MY_EXPORTER destination 192.168.1.100 (Your monitor’s IP) transport udp 2055 source Loopback0
On pfSense/OPNsense: Services > NetFlow > Enable + set collector IP. On Ubiquiti UniFi: System > Advanced > NetFlow Export (IP + Port 2055). Before you build a whole stack, point your router’s NetFlow export to a laptop running ntopng in a Docker container :
Plixer’s Scrutinizer is the gold standard. The free version is limited to and keeps data for 5 hours of raw detail (aggregated views go back 30 days). For most SMBs and labs, 10k fps is huge.
The security investigation tools. You can drill from “High UDP traffic” straight into a flow grid, apply a filter for “Deny” actions, and pivot to a geo-map. No other free tool matches its threat-hunting workflow.

