Cisco introduced Netflow in 1996. NetFlow makes it possible to collect IP network traffic on the incoming and outgoing interface. By analysing the data provided by NetFlow, a network administrator can determine, for example, the source and objective of the traffic, the class of service, the causes of congestion or malware.

Activate the netflow top talkers function 

The command show ip flow top-talkers can be used to display the top talkers. This command is a practical tool for analysing DDoS attacks and bandwidth problems. The results can also be sorted by packets or bytes for a faster analysis. This can be implemented as follows 

ip flow-top-talkers
top 50
sort-by packets