If you're considering actual 'netflow' data, I'm not really sure it will help with your requirements. The smallest unit is the 'flow' which could include many UDP packets and has only *flow* start and end times. Cisco's IP SLA might help. See: http://www.cisco.com/en/US/docs/ios/12_4/ip_sla/configuration/guide/hsjitter... Joe From: Shacolby Jackson <shacolby@bluejeansnet.com> To: nanog@nanog.org Date: 02/01/2011 07:21 PM Subject: netflow analysis for jitter and packet loss? What tools are people most happy with? Specifically I'm hoping to mirror a port and later see if I can detect any inbound jitter or possibly even out of order udp datagrams. At first glance it doesn't look like ntop or plixer can provide that level of detail. Any suggestions? -shac