Re: [Nfdump-discuss] v5 flows next hop ip
netflow collecting and processing tools
Brought to you by:
phaag
|
From: Peter H. <ph...@us...> - 2013-08-12 06:22:49
|
Next hop IP is an optional field. You need to tell nfcapd, to include the next hop into the data. Add the proper -T 4 extension when starting up nfdump. -> See nfcapd. You may add -Tall to get everything, if disk space is not an issue. - Peter On 7/25/13 W30 19:27, Jordan Whited wrote: > next-hop IP is included in v5 flow records but it does not appear to be a field for an nfdump flow record. Is this > included for v9 or ipfix/v10 by chance? > > nfdump 1.6.10 > > Flags = > export sysid = > size = > first = > last = > msec_first = > msec_last = > src addr = > dst addr = > src port = > dst port = > fwd status = > tcp flags = > proto = > (src)tos = > (in)packets = > (in)bytes = > input = > output = > src as = > dst as = > > > > ------------------------------------------------------------------------------ > See everything from the browser to the database with AppDynamics > Get end-to-end visibility with application monitoring from AppDynamics > Isolate bottlenecks and diagnose root cause in seconds. > Start your free trial of AppDynamics Pro today! > http://pubads.g.doubleclick.net/gampad/clk?id=48808831&iu=/4140/ostg.clktrk > > > > _______________________________________________ > Nfdump-discuss mailing list > Nfd...@li... > https://lists.sourceforge.net/lists/listinfo/nfdump-discuss > -- -- Be nice to your netflow data |