Re: Cflowd vs Netflow vs ....

From: Christian Hammers (ch@westend.com)
Date: Fri Jan 26 2001 - 06:12:33 PST

  • Next message: Peter Francis: "reparsing raw flow data with cflowdcollect"

    On Fri, Jan 26, 2001 at 08:06:01PM +0600, Alex Shavkun wrote:
    > It's very interesting. We want to begin release our own netflow collector and
    > sql analyser/accounting too (Oracle based). What base do you use (cfdcollect
    > sourse code or youself one)?
    We wrote our own collector in C as this collector is really very small and
    just reads UDP packages and writes them nearly as-is into a MySQL database.
    BTW: As far as I read mysql is much faster than Oracle. Although Oracle has
    of course *many* features still missing in MySQL so it would be worth to
    consider using MySQL for netflow and export the then summarized data somewhen
    back to the Oracle for further accounting.
    The program that calculates free- (two subnets on one router), intern- (i.e.
    in our network) and extern-traffic is written in Perl. It takes about 2h
    to process the 1-2GB raw data we get per day and gives us per network
    statistics.

    > Alex.
    bye,

     -christian-

    -- 
    Christian Hammers    WESTEND GmbH - Aachen und Dueren     Tel 0241/701333-0
    ch@westend.com     Internet & Security for Professionals    Fax 0241/911879
               WESTEND ist CISCO Systems Partner - Premium Certified
    --
    cflowd mailing list
    cflowd@caida.org
    



    This archive was generated by hypermail 2b29 : Fri Jan 26 2001 - 06:20:41 PST