Dear pmacct users, I'm trying to connect pmacct on a linux system to a machine running netflowanalyser v7.
My linux system configuration is a PC with 3 gigabit ports, one for administrive use: the other two are bridged. I plan to implement some bandwidth control on the egress interface of this bridge, but for now i'm just finding a suitable monitoring package. Netflow analyser does everything I need. To get enough and the correct data to this host using pmacct is proving difficult. I have a single /24 IP network and wish to report on upstream and downstream traffic and link utilisation from this. I imagine it will be a simple configuration file but all that I've tried have not been successful. Do I make two sprobe instances, say [in] and [out] each filtered by src and dest network? or do I attach an incoming filter to each of the bridged interfaces and sprobe for each interface? what do I use as an aggregate if any? I'm guessing [src|dst]_host so I can have per host resolution at the monitor. any tips on how to configure this would be great. Additionally, when netflowanalyser receives some data it doesn't show correct interface names. When it polls back using SNMP they are incorrect also. How is the interface represneted in sflow? by localname or local index? thanks for any insight Best regards Rob _______________________________________________ pmacct-discussion mailing list http://www.pmacct.net/#mailinglists
