Hi Sergio, On Tue, May 04, 2010 at 08:44:55AM -0300, Sergio Charpinel Jr. wrote:
> Yes, it is working, thanks. Good! > And I analyzed some flows related to expiring orphan, and most of them > seems to be related to torrents, but I'm not sure. > > [ ... ] > > WARN: expecting flow '817086981' but received '817086983' > collector=127.0.0.1:2100 agent=127.0.0.1:0 > INFO: unable to read next Flowset; incomplete NetFlow v9 packet: > nfacctd=127.0.0.1:2100 agent=127.0.0.1:49586 Can you please send over privately two packet captures - in libpcap/ tcpdump format, full frame size: * one capturing some torrent traffic, so that i can replay it in a testbed and see if i can reproduce and validate the behaviour. * the other capturing some NetFlow packets delivered to nfacctd so that i can look into them with a packet analyzer. It should never happen that nfacctd is unable to parse NetFlow datagrams produced by nfprobe. Cheers, Paolo _______________________________________________ pmacct-discussion mailing list http://www.pmacct.net/#mailinglists
