Hi Oliver, > Ok, so have I completely misunderstood the purpose of sFlow? Currently > we > are using pmacctd to record every single byte and packet that crosses > our > network via mirror ports on the switches. Does sFlow only generate a > "summary" of the traffic? For our purposes it will need to report > every byte > and packet, just as our pmacctd setup currently does. > > Maybe I am just not understanding the purpose of sFlow...
I'm not a sFlow expert and surelly Paolo will be able to help you more on this BUT in general neither NetFlow nor sFlow are valid for this. Both of them are more "flow" based than "packet" based and in general they will only report on header information, not complete payload (actually trying to get all payload information will surelly kill the performance of the link itself). After that you have the option of using sampling or not, and different kinds of them. NetFlow allows to work without sampling, and this is valid in low speed links or high end hardware, but i think sFlow itself is always sampled. At the same time the sampling can be just dumb (1 out of tenth) or intelligent (they consider size) but in both cases they loose precision. And last, you have to consider were to store all this info. If the probe doesnt sample, will you in the server? etc etc Hope it helps -------------------------------------------- Jaime Nebrera - [EMAIL PROTECTED] Consultor TI - ENEO Tecnologia SL Pol. PISA - C/ Manufactura 6, P1, 3B Mairena del Aljarafe - 41927 - Sevilla Telf.- (+34) 955 60 11 60 / 619 04 55 18 _______________________________________________ pmacct-discussion mailing list http://www.pmacct.net/#mailinglists
