-
Notifications
You must be signed in to change notification settings - Fork 29
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Push flows to ntopng #12
Conversation
Ntopng is a an open-source traffic analyser: https://www.ntop.org/products/traffic-analysis/ntop/ Unfortunately, it cannot ingest Netflow data directly, instead, it requires a payware component (Nprobe) to tranlate Netflow to JSON encapsulated in ZeroMQ messages. This patch allows softflowd to generate those messages directly, allowing Ntopng to be used without the need for the payware component. Signed-off-by: Alastair D'Silva <alastair@d-silva.org>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank you for sending PR.
I wrote a comment for getopt options. I approve your commit, however I will change the getopt parameter and some points.
" -v 1|5|9|10|psamp NetFlow export packet version\n" | ||
" 10 means IPFIX and psamp means PSAMP (packet sampling)\n" | ||
" -v 1|5|9|%d|%d|psamp NetFlow export packet version\n" | ||
" %d means IPFIX, %d means NTOPNG (if supported),\n" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I prefer to use "ntopng" instead of "11". The version number in IPFIX header is 10 defined in RFC5101 and 7011, therefore it is not unnatural for using 10 for IPFIX.
However notpng is non-standard software. It is unnatural for using 11 for ntopng, I think.
Does anyone know what version of ntop supports this? I've tried to different ones from 3.x and 4.x with no luck. |
Hi
In May I tried to push flows to ntop but the maintainer explained to me in
ticket #25 that this functionality doesn't exist.
Kind regards,
…On Fri, Jul 3, 2020 at 11:35 AM tusc ***@***.***> wrote:
Does anyone know what version of ntop supports this? I've tried to
different ones from 3.x and 4.x with no luck.
—
You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub
<#12 (comment)>, or
unsubscribe
<https://github.com/notifications/unsubscribe-auth/AD5RHJMR2XR3FVLAT7V2KXTRZYJGPANCNFSM4IIMPHMQ>
.
|
This patch exports data to ntopng, not ntop, they are different codebase. |
Yes, I tried without success to use softflowd instead of nprobe to
export/transform flows to ntopng.
Regards
…On Fri, Jul 3, 2020 at 4:01 PM deece ***@***.***> wrote:
This patch exports data to ntopng, not ntop, they are different codebase.
—
You are receiving this because you commented.
Reply to this email directly, view it on GitHub
<#12 (comment)>, or
unsubscribe
<https://github.com/notifications/unsubscribe-auth/AD5RHJOQTN64VS6VST5JVZDRZZIMDANCNFSM4IIMPHMQ>
.
|
@deece , I meant to say ntopng, not ntop. Regardless it does not work with ntopng 3.x or 4.x. Is there a version it is intended to work with? |
hi guys |
Ntopng is a an open-source traffic analyser:
https://www.ntop.org/products/traffic-analysis/ntop/
Unfortunately, it cannot ingest Netflow data directly, instead,
it requires a payware component (Nprobe) to tranlate Netflow to JSON
encapsulated in ZeroMQ messages.
This patch allows softflowd to generate those messages directly,
allowing Ntopng to be used without the need for the payware component.
Signed-off-by: Alastair D'Silva alastair@d-silva.org