Hi, I installed FlowViewer and Silk.
Silk is working and I see flow-files in /var/flows, but I can't collect data via FlowMonitor Collector.
In logs I see next:
0 Monitors had a zero value. 0 Monitors had a positive value. 0 IPFIX, 0 Flows Active, 0 Linear.
If I run this:
rwpackchecker --print-all /var/flows/test/int2int/2019/04/09/int2int-S0_20190409.23
Output:
0/228671 flows are bad or unusual
0 flows where BPP Calculation is incorrect
0 flows where Elapsed Time > 4096
0 flows where Byte/Packet Ratio < 1
0 flows where Byte/Packet Ratio > 16384
0 flows where Byte/Second Ratio < 0
0 flows where Byte/Second Ratio > 4294967295
0 flows where Packet Count < 1
0 flows where Packet Count > 67108864
0 flows where Byte Count < 1
0 flows where Byte Count > 4294967295
0 flows where TCP Byte/Packet Ratio < 1
0 flows where TCP Byte/Packet Ratio > 16384
0 flows where UDP Byte/Packet Ratio < 1
0 flows where UDP Byte/Packet Ratio > 16384
0 flows where ICMP Byte/Packet Ratio < 1
0 flows where ICMP Byte/Packet Ratio > 16384
Thanks in advance for your help
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
Hi, I installed FlowViewer and Silk.
Silk is working and I see flow-files in /var/flows, but I can't collect data via FlowMonitor Collector.
In logs I see next:
0 Monitors had a zero value. 0 Monitors had a positive value. 0 IPFIX, 0 Flows Active, 0 Linear.
If I run this:
rwpackchecker --print-all /var/flows/test/int2int/2019/04/09/int2int-S0_20190409.23
Output:
0/228671 flows are bad or unusual
0 flows where BPP Calculation is incorrect
0 flows where Elapsed Time > 4096
0 flows where Byte/Packet Ratio < 1
0 flows where Byte/Packet Ratio > 16384
0 flows where Byte/Second Ratio < 0
0 flows where Byte/Second Ratio > 4294967295
0 flows where Packet Count < 1
0 flows where Packet Count > 67108864
0 flows where Byte Count < 1
0 flows where Byte Count > 4294967295
0 flows where TCP Byte/Packet Ratio < 1
0 flows where TCP Byte/Packet Ratio > 16384
0 flows where UDP Byte/Packet Ratio < 1
0 flows where UDP Byte/Packet Ratio > 16384
0 flows where ICMP Byte/Packet Ratio < 1
0 flows where ICMP Byte/Packet Ratio > 16384
Thanks in advance for your help
Looks like maybe you haven't set up a FlowMonitor? Can you successfully use FlowViewer and FlowGrapher?
Thanks, Joe
Maybe I don't setup a FLowMonitor, but how I can do it? I dont see any data in FlowViewer. I did all items from chapter 2-installation.
Last edit: Timur 2019-04-11
It looks like you may have SiLK set up OK. Are you receiving data and are the files growing?
What does your 'var/flows/...' (or similar) directory look like? I'm trying to find out what you've named your devices.
I see you set something up called 'test'. Can you also provide your FlowViewer_Configuration.pm file as well?
Can I send the file to you personally?
Sure. You should have a device set to 'test', i.e., @ipfix_devices = ("test")
I would be glad to look over the whole config file.
My email is: jloiacon@gmail.com