Menu

Problem with FlowMonitor Collector

Timur
2019-04-10
2019-04-12
  • Timur

    Timur - 2019-04-10

    Hi, I installed FlowViewer and Silk.
    Silk is working and I see flow-files in /var/flows, but I can't collect data via FlowMonitor Collector.
    In logs I see next:
    0 Monitors had a zero value. 0 Monitors had a positive value. 0 IPFIX, 0 Flows Active, 0 Linear.
    If I run this:
    rwpackchecker --print-all /var/flows/test/int2int/2019/04/09/int2int-S0_20190409.23
    Output:
    0/228671 flows are bad or unusual
    0 flows where BPP Calculation is incorrect
    0 flows where Elapsed Time > 4096
    0 flows where Byte/Packet Ratio < 1
    0 flows where Byte/Packet Ratio > 16384
    0 flows where Byte/Second Ratio < 0
    0 flows where Byte/Second Ratio > 4294967295
    0 flows where Packet Count < 1
    0 flows where Packet Count > 67108864
    0 flows where Byte Count < 1
    0 flows where Byte Count > 4294967295
    0 flows where TCP Byte/Packet Ratio < 1
    0 flows where TCP Byte/Packet Ratio > 16384
    0 flows where UDP Byte/Packet Ratio < 1
    0 flows where UDP Byte/Packet Ratio > 16384
    0 flows where ICMP Byte/Packet Ratio < 1
    0 flows where ICMP Byte/Packet Ratio > 16384

    Thanks in advance for your help

     
  • Joe Loiacono

    Joe Loiacono - 2019-04-10

    Looks like maybe you haven't set up a FlowMonitor? Can you successfully use FlowViewer and FlowGrapher?

    Thanks, Joe

     
  • Timur

    Timur - 2019-04-11

    Maybe I don't setup a FLowMonitor, but how I can do it? I dont see any data in FlowViewer. I did all items from chapter 2-installation.

     

    Last edit: Timur 2019-04-11
  • Joe Loiacono

    Joe Loiacono - 2019-04-11

    It looks like you may have SiLK set up OK. Are you receiving data and are the files growing?

    What does your 'var/flows/...' (or similar) directory look like? I'm trying to find out what you've named your devices.

     
  • Joe Loiacono

    Joe Loiacono - 2019-04-11

    I see you set something up called 'test'. Can you also provide your FlowViewer_Configuration.pm file as well?

     
    • Timur

      Timur - 2019-04-11

      Can I send the file to you personally?

       
  • Joe Loiacono

    Joe Loiacono - 2019-04-12

    Sure. You should have a device set to 'test', i.e., @ipfix_devices = ("test")

    I would be glad to look over the whole config file.

    My email is: jloiacon@gmail.com

     

Log in to post a comment.