Interesting - do you have a lot of long living tcp connections? What intervals do you use and what bandwith are you monitoring?
Thanks - Peter On 28.10.15 09:18, Maqbool Hashim wrote: > Hi, > > > I am running nfpcapd to convert live packet dump from a monitored switch port > into nfdump format for later analysis. I find that nfpcapd rapidly consumes > all available memory on the system and has to be killed or gets killed by the > OOM killer. > > > I am running NSEL-NEL1.6.13 version of nfdump. > > > It is running on a Ubuntu system with a 3.16.0-34-generic kernel. > > > I switched to using a different collector that captures the full traffic and > outputs as netflow to nfcapd as a workaround. However thought you may be > interested to know about this. > > > Let me know if you require any further information. > > > > ------------------------------------------------------------------------------ > > > > _______________________________________________ > Nfdump-discuss mailing list > Nfdump-discuss@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/nfdump-discuss > -- Be nice to your netflow data. Use NfSen and nfdump :) ------------------------------------------------------------------------------ _______________________________________________ Nfdump-discuss mailing list Nfdump-discuss@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/nfdump-discuss