VCF Operations for Networks
VMware NSX
This is expected behavior. When a firewall rule changes, VCF Operations for Networks does not immediately remove the association with the old rule. There is a default time window of 6 hours before the old rule metadata is purged and the flow record is updated exclusively with the new rule ID.
In environments using NSX-T Federation, multiple rules may also appear if rules are applied by both the Global Manager and a Local Manager.
No technical action is required as the system is behaving as designed.