Interesting - do you have a lot of long living tcp connections?
What intervals do you use and what bandwith are you monitoring?

Thanks

        - Peter

On 28.10.15 09:18, Maqbool Hashim wrote:
> Hi,
> 
> 
> I am running nfpcapd to convert live packet dump from a monitored switch port 
> into nfdump format for later analysis.  I find that nfpcapd rapidly consumes 
> all available memory on the system and has to be killed or gets killed by the 
> OOM killer.
> 
> 
> I am running NSEL-NEL1.6.13 version of nfdump.
> 
> 
> It is running on a Ubuntu system with a 3.16.0-34-generic kernel.
> 
> 
> I switched to using a different collector that captures the full traffic and 
> outputs as netflow to nfcapd as a workaround.  However thought you may be 
> interested to know about this.
> 
> 
> Let me know if you require any further information.
> 
> 
> 
> ------------------------------------------------------------------------------
> 
> 
> 
> _______________________________________________
> Nfdump-discuss mailing list
> Nfdump-discuss@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/nfdump-discuss
> 

-- 
Be nice to your netflow data. Use NfSen and nfdump :)

------------------------------------------------------------------------------
_______________________________________________
Nfdump-discuss mailing list
Nfdump-discuss@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfdump-discuss

Reply via email to