Re: cfdcollect produces 0 size file ?

From: Wang Lijing (wanglj@mmlab.snu.ac.kr)
Date: Thu May 03 2001 - 01:42:28 PDT

  • Next message: Gustavo Torres: "RFC´s?"

    > What does flowdump do then ?
    >
    > If I run flowdump on
    > /usr/local/arts/data/cflowd/flows/xxx.xxx.xxx.xxx.flows.x, it also produces
    > nothing?
     
    flowdump is a utility for selecting and viewing raw flows from a cflowd flow file. When you run flowdump on a xxx.xxx.xxx.xxx.flows.x, you can see such kind following output, which are just those fields of NetFlow.
    FLOW
      index: 0xc7ffff
      router: xxx.xxx.xxx.xxx
      src IP: xxx.xxx.xxx.xxx
      dst IP: xxx.xxx.xxx.xxx
      input ifIndex: 8
      output ifIndex: 3
      src port: 6346
      dst port: 1493
      pkts: 7
      bytes: 735
      IP nexthop: xxx.xxx.xxx.xxx
      start time: Thu May 3 16:40:12 2001
      end time: Thu May 3 16:40:13 2001
      protocol: 6
      tos: 0
      src AS: xxx
      dst AS: xxx
      src masklen: 0
      dst masklen: 24
      TCP flags: 0x1f
      engine type: 0
      engine id: 0
      

    Lijing Wang

    ----- Original Message -----
    From: "Michael Bellears" <mbellears@staff.datafx.com.au>
    To: "'Frank Hellemink'" <fhellemink@chello.com>; "Michael Bellears" <mbellears@staff.datafx.com.au>; <cflowd@caida.org>
    Sent: Thursday, May 03, 2001 7:51 AM
    Subject: RE: cfdcollect produces 0 size file ?

    > Thanks for the reply Frank.
    >
    > Just to confirm a few points ->
    >
    > cfdcollect - Extracts the raw data in
    > /usr/local/arts/data/cflowd/flows/xxx.xxx.xxx.xxx.flows.x
    > then dumps it into
    > /usr/local/arts/data/cflowd/flows/xxx.xxx.xxx.xxx/arts.20010502 in a
    > readable format ?
    >
    > What does flowdump do then ?
    >
    > If I run flowdump on
    > /usr/local/arts/data/cflowd/flows/xxx.xxx.xxx.xxx.flows.x, it also produces
    > nothing?
    >
    > Am I doing something blatantly wrong here ?
    >
    > Regards,
    > MB
    >

    --
    cflowd mailing list
    cflowd@caida.org
    



    This archive was generated by hypermail 2b29 : Thu May 03 2001 - 02:01:38 PDT