Correction, I use NetFlow version 9.
Also, the newer version of ntop is called ntop-ng.
These documents describe the format of the output of a version 9 packet:
http://www.cisco.com/en/US/technologies/tk648/tk362/technologies_white_pape…
http://www.cisco.com/c/en/us/td/docs/net_mgmt/netflow_collection_engine/3-6…
- KB3VWG