<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Case &#187; netflow</title>
	<atom:link href="http://case.net.ru/tag/netflow/feed/" rel="self" type="application/rss+xml" />
	<link>http://case.net.ru</link>
	<description>Just another technical weblog</description>
	<lastBuildDate>Sun, 29 Jan 2012 08:48:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Работаем с Netflow</title>
		<link>http://case.net.ru/2009/05/13/netflow/</link>
		<comments>http://case.net.ru/2009/05/13/netflow/#comments</comments>
		<pubDate>Wed, 13 May 2009 14:14:11 +0000</pubDate>
		<dc:creator>Case</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[flow-tools]]></category>
		<category><![CDATA[netflow]]></category>
		<category><![CDATA[softflowd]]></category>

		<guid isPermaLink="false">http://case.net.ru/?p=536</guid>
		<description><![CDATA[Коллектор flow-capture Установка: $ cd /usr/ports/net-mgmt/flow-tools $ make install clean Прописываем в rc.conf: flow_capture_enable=&#34;YES&#34; flow_capture_localip=&#34;127.0.0.1&#34; Запускаем: $ /usr/local/etc/rc.d/flow_capture start Starting flow_capture. Проверяем: $ sockstat -l4&#124;grep flow flowtoolsflow-captu 43982 1 udp4 127.0.0.1:8787 *:* &#160; Сенсор softflowd Установка: $ cd /usr/ports/net-mgmt/softflowd $ make install clean Добавляем стартовый скрипт в /usr/local/etc/rc.d: #!/bin/sh # Softflowd loader &#160; case $1 [...]]]></description>
			<content:encoded><![CDATA[<p><b>Коллектор flow-capture</b></p>
<p>Установка:</p>

<div class="wp_syntax"><div class="code"><pre class="cli" style="font-family:monospace;">$ cd /usr/ports/net-mgmt/flow-tools
$ make install clean</pre></div></div>

<p>Прописываем в rc.conf:</p>

<div class="wp_syntax"><div class="code"><pre class="cli" style="font-family:monospace;">flow_capture_enable=&quot;YES&quot;
flow_capture_localip=&quot;127.0.0.1&quot;</pre></div></div>

<p>Запускаем:</p>

<div class="wp_syntax"><div class="code"><pre class="cli" style="font-family:monospace;">$ /usr/local/etc/rc.d/flow_capture start
Starting flow_capture.</pre></div></div>

<p>Проверяем:</p>

<div class="wp_syntax"><div class="code"><pre class="cli" style="font-family:monospace;">$ sockstat -l4|grep flow
flowtoolsflow-captu 43982 1  udp4   127.0.0.1:8787        *:*</pre></div></div>

<h1>&nbsp;</h1>
<p><b>Сенсор softflowd</b></p>
<p>Установка:</p>

<div class="wp_syntax"><div class="code"><pre class="cli" style="font-family:monospace;">$ cd /usr/ports/net-mgmt/softflowd
$ make install clean</pre></div></div>

<p>Добавляем стартовый скрипт в /usr/local/etc/rc.d:</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #666666; font-style: italic;">#!/bin/sh</span>
<span style="color: #666666; font-style: italic;"># Softflowd loader</span>
&nbsp;
<span style="color: #000000; font-weight: bold;">case</span> $<span style="color: #000000;">1</span> <span style="color: #000000; font-weight: bold;">in</span>
        start<span style="color: #7a0874; font-weight: bold;">&#41;</span>
                softflowd <span style="color: #660033;">-i</span> vlan3 <span style="color: #660033;">-n</span> 127.0.0.1:<span style="color: #000000;">8787</span>
                <span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">'Softflowd is loaded'</span>
                <span style="color: #000000; font-weight: bold;">;;</span>
        stop<span style="color: #7a0874; font-weight: bold;">&#41;</span>
                softflowctl shutdown
                <span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">'Softflowd is unloaded'</span>
                <span style="color: #000000; font-weight: bold;">;;</span>
        status<span style="color: #7a0874; font-weight: bold;">&#41;</span>
                softflowctl statistics
                <span style="color: #000000; font-weight: bold;">;;</span>
        <span style="color: #000000; font-weight: bold;">*</span><span style="color: #7a0874; font-weight: bold;">&#41;</span>
                <span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;Usage: <span style="color: #780078;">`basename $0`</span> {start|stop|status}&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;&amp;</span><span style="color: #000000;">2</span>
                <span style="color: #000000; font-weight: bold;">;;</span>
<span style="color: #000000; font-weight: bold;">esac</span>
<span style="color: #7a0874; font-weight: bold;">exit</span> <span style="color: #000000;">0</span></pre></div></div>

<p>Основные ключи для softflowd:</p>

<div class="wp_syntax"><div class="code"><pre class="cli" style="font-family:monospace;">     -n host:port
             Specify the host and port that the accounting datagrams are to be 
             sent to.
     -i interface
             Specify a network interface on which to listen for traffic.
             Either the -i or the -r options must be specified.</pre></div></div>

<p>Запускаем:</p>

<div class="wp_syntax"><div class="code"><pre class="cli" style="font-family:monospace;">$ /usr/local/etc/rc.d/softflowd start
Softflowd is loaded</pre></div></div>

<h1>&nbsp;</h1>
<p><b>Чтение данных</b></p>
<p>В каталоге /var/db/flows будут скапливаться файлы с данными.<br />
Пример выборки &#8211; статистика по объёму трафика за один час:</p>

<div class="wp_syntax"><div class="code"><pre class="cli" style="font-family:monospace;">$ flow-cat -t &quot;17:00&quot; -T &quot;18:00&quot; /var/db/flows/2009/2009-05/2009-05-13/ | flow-stat -f 15 
#  --- ---- ---- Report Information --- --- ---
#
# Fields:    Total
# Symbols:   Disabled
# Sorting:   None
# Name:      short summary
#
# Args:      flow-stat -f 15 
#
#
# Octets            Packets             MBytes
#
144830237           699315              144.830</pre></div></div>

<p>Ссылки:</p>
<ul>
<li><a href="http://nag.ru/2006/0205/0205.shtml">http://nag.ru/2006/0205/0205.shtml</a></li>
<li><a href="http://xgu.ru/wiki/NetFlow">http://xgu.ru/wiki/NetFlow</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://case.net.ru/2009/05/13/netflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
