When a network aggregator sends NetFlow, the traffic originates from as little as one interface on the aggregator. Are there any potential issues with this? I could create custom virtual interfaces aligned with the networks where the traffic is coming from but I'm not sure how much value that will add.
I don't believe there would be any issues with this. If the network aggregator traffic has unique source IP addresses it will create unique devices in NFA. If its only only 1 source IP address it will only create one device.
Ideally you would want to see a unique input and output interface to represent IN and OUT data in NFA. Without that I am not sure how much value the data would have. We would have to see what the flow data looks like in a pcap to understand how it would look in NFA.