> Source: [sk174254](https://support.checkpoint.com/results/sk/sk174254)

# sk174254 - Netflow Collector does not show Inbound flows

| Property | Value |
|----------|-------|
| Solution ID | sk174254 |
| Date Created | 2021-07-07 |
| Last Modified | 2022-07-13 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1500, 1600, 1800 |

## Symptoms

- * Configured Netflow collector does not show any inbound flows.

* Netflow collector shows only outbound flows.

## Cause

In locally managed appliances only:  

For Netflow configuration to work, traffic must be accelerated, at least partially, and the logging level set to 'Accounting'.   

Incoming Traffic policy logging is not set to 'Accounting", and there is no option to set it.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.   
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.

<br />

Hotfix adds the option to set logging to 'Accounting'.  

**Note** - Incoming flows will only show NAT'd address for destinations that are NAT'd behind the gateway.

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
