I upgraded a 4.9 box to 5.3 recently and found pflow is behaving in new ways.
Pflow used to report the source IP before NAT was performed. Today, it reports the translated source IP rather than the untranslated one. I was using it to keep a record of NAT translations, which isn't possible now. Anyone know if this was a desired, or an accidental change ?