Questions tagged [netflow]
53 questions
0
votes
1 answer
Memory leak in flow_fanout flow_capture. And strange ip in flow_capture output
On my freebsd box:
#uname -rimp
9.1-STABLE amd64 amd64 GENERIC
flow_tools:
> pkg_info -x flow
Information for flow-tools-0.68_7:
Comment:
Suite of tools and library to work with netflow data
Description:
Tools to capture, replicate, print,…

Korjavin Ivan
- 2,250
- 2
- 26
- 41
0
votes
4 answers
Netflow packet includes zero port numbers?
What does a zero source port number indicate? Can Netflow tell about something a connection that is not TCP or UDP?
Thanks.

Spresso
- 21
- 4
0
votes
0 answers
How to have multiple instances of filebeat load balance Netflow input?
I have a very high volume Netflow input stream, and I was hoping that I could run multiple instances of Filebeat and load-balance the Netflow traffic over the Filebeat instances, and then write to a single remote Elasticsearch.
I've read about…

Rayne
- 211
- 2
- 14
0
votes
0 answers
Trying to understand nfdump output
I am trying to figure out meaning in a nfdump output, but I cannot seem to find any sources for this. For now I am mostly trying to understand what some of the categories mean.
What I have is a basic output with the following fields: Date first seen…

arnby
- 1
- 1
0
votes
0 answers
Solarwinds Netflow Generator is crashing with file not found
I am using this tool from Solar Winds to generate v9 Netflow events.
It was working until an OS update a few days ago. Now, it starts, but when I generate events it crashes every time. I have tried running it as Administrator and my regular…

KaizenSoze
- 123
- 4
0
votes
2 answers
Netflow records with Destination Ports 1025,257 and Protocol as ipv6-icmp
I have some Netflow records from a bunch of routers. The records contain IPv6 flows and there are entries with protocol as ipv6-icmp and their destination port values as 0, 1025 and 257. I know from this link that the value of 0 for ipv6-icmp in…

Said Jawad
- 1
- 2
-1
votes
1 answer
Udp session Netflow
How netflow defines the end of the udp session. That is, as I understand, there must be some timeout in the absence of requests from the dynamic port with the passage of time after which a new session for this port is formed. If yes, how it is…

egor
- 3
- 2
-1
votes
2 answers
Is ntop's sflow support equivalent to netflow?
I've seen conflicting information from various dates and I'm having trouble determining if ntop supports sflow the same way it supports netflow or if it is somehow handicapped and not really worth giving the effort.
We're just getting started at…

flickerfly
- 2,753
- 3
- 25
- 27