Comments (5)
nfdump handles 8bytes (64bit) counters already for years. INternally nfdump uses only 64bit counters.
If the counters are wrong, this mus be something different. Please send me a pcap captured at the collector side to check.
from nfdump.
Hi,
Here you have a pcap file and the debug output from my perl script parsing the same pcap file.
If you want to make it easy for you to see the difference when 64 bit fields for IN_Bytes and OUT_bytes is used use "dst host 130.240.19.2" and if source starts with 130.240.x.x then it is processed by Fortigate. Else it processed by Cisco with normal 32bit counters.
130.240.19.2 is one of our DNS servers
Från: Peter Haag [email protected]
Skickat: den 6 maj 2016 14:18
Till: phaag/nfdump
Kopia: Thomas Nilsson; Author
Ämne: {Disarmed} Re: [phaag/nfdump] 64 bit counters for IN_BYTES and OUT_BYTES (#22)
nfdump handles 8bytes (64bit) counters already for years. INternally nfdump uses only 64bit counters.
If the counters are wrong, this mus be something different. Please send me a pcap captured at the collector side to check.
You are receiving this because you authored the thread.
Reply to this email directly or view it on GitHubhttps://github.com//issues/22#issuecomment-217425141
from nfdump.
from nfdump.
Hi,
Are you looking into this issue even when you closed it before I had the time to reply, or do I need to open a new ticket?
from nfdump.
Could be that Fortigate don’t send TCP flags in their export. If this field is missing how do your code cope with it?
from nfdump.
Related Issues (20)
- geolookup truncate autonomous_system_organization name HOT 5
- Destination Location header in formated output is called "Src IP location info" HOT 1
- Feature Request: autonomous_system_organization name in nfdump output HOT 7
- valgrind issue in lz4, while using -a aggregation HOT 9
- nftrack [regression]: -r <file> aborts if <file> is not in current directory HOT 1
- Nfcapd's packet repeater doesn't seem to work HOT 2
- Memory leak in nfcapd HOT 3
- How to capture the ASN of Netflow HOT 10
- Unidentified AS 0 HOT 2
- Nfdump collecting interval HOT 2
- Nfanon and filter mode? HOT 2
- request/ selective anonymization HOT 3
- request: nfreplay lose exporter IP info HOT 6
- tiny build issue in make: ../../ylwrap: line 176: yacc: command not found HOT 2
- missing nfcapd instance for device HOT 1
- ZSTD compression HOT 34
- Include source name and/or source IP in "Unexpected record count in header" error HOT 4
- flow filter not working HOT 1
- Header not CSV but data is CSV with -o <fmt> HOT 2
- AS statistics doesn't work without filter HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from nfdump.