-
-
Notifications
You must be signed in to change notification settings - Fork 206
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Sampling logic applied to un-sampled records #212
Comments
Hmm .. difficult to tell from the what I see. Would it possible for you to send my a pcapd trace with all templates and some data records off list? You may use the email in the AUTHORS file. |
The exporter announces sampling with option elements IDs #34/#35. If you have sampled and unsampled data from the same exporter, you need to You can verify exporter and sampler any time later with the query: |
Any update on that otherwise I close the ticket |
Peter
Many thanks, we will investigate the results with newer version.
Thank you.
…On Sat, 18 Apr 2020 at 17:30, Peter Haag ***@***.***> wrote:
Any update on that otherwise I close the ticket
—
You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
<#212 (comment)>, or
unsubscribe
<https://github.com/notifications/unsubscribe-auth/ABRNW45URH3GH6JC5UZMZ5TRNFJJPANCNFSM4LUTBSLQ>
.
|
I close the issue. If you still need further invesigate this issue, please re-open it again. |
NFDump is processing UnSampled Records as sampled.
This NFDUMP output shows "Sampled" flag set despite the NF record referring to an unsampled template.
The result is incorrect statistics being calculated, in this case 0 bytes.
Note: the device is sending several Netflow templates, some are sampled and some not.
Below is the
Data Record for the above flow as Decoded in Wireshark for the above packet
FlowSet 1 [id=258] (1 flows)
FlowSet Id: (Data) (258)
FlowSet Length: 72
[Template Frame: 19 (received after this frame)]
Flow 1
Octets: 40
Post Octets: 40
Packets: 1
Post Packets: 1
[Duration: 3.000000000 seconds (switched)]
StartTime: 3583956.452000000 seconds
EndTime: 3583959.452000000 seconds
SrcPort: 179
DstPort: 54364
InputInt: 0
OutputInt: 724
Protocol: TCP (6)
Post Ip Diff Serv Code Point: 255
Classification Engine ID: PANA-L7-PEN (20)
Selector ID: 0000304400000000
Unknown Field Type: Type 66: Value (hex bytes): 00 00 00 00
Unknown Field Type: Type 65: Value (hex bytes): 0e 0c
Forwarding Status
11.. .... = ForwardingStatus: Consume (3)
..00 0011 = ForwardingStatusConsumeCode: Terminate For us (3)
Flow End Reason: End of Flow detected (3)
SrcAddr: xx.xx.xx.xx (xx.xx.xx.xx)
DstAddr: yy.yy.yy.yy (yy.yy.yy.yy)
Padding: 00
Below is the
Template Record for the above (template 258) for the above Data Record
Note it does NOT include Fields 34 or 35.
We also have interspersed with the above templates
From the same router and in the same template packets the following Template record which does include the 34 and 35 Fields.
Below is the
copy of the Data Records which make use of the above Template but create no NFDump results as they have imcomplete data they appear to contain some sort of summary flow records (example is wireshark interpreation)
Frame 1: 102 bytes on wire (816 bits), 102 bytes captured (816 bits)
Ethernet II, Src: XX.XX.XX.XX Dst: XX.XX.XX.XX
Internet Protocol Version 4, Src: XX.XX.XX.XX Dst: XX.XX.XX.XX
User Datagram Protocol, Src Port: 4091, Dst Port: 9995
Cisco NetFlow/IPFIX
Version: 9
Count: 1
SysUptime: 3583899.052000000 seconds
Timestamp: Mar 13, 2020 14:12:29.000000000 AEDT
CurrentSecs: 1584069149
FlowSequence: 2
SourceId: 91
FlowSet 1 [id=256] (1 flows)
FlowSet Id: (Data) (256)
FlowSet Length: 40
[Template Frame: 19 (received after this frame)]
Flow 1
ScopeSystem: 0001
OctetsExp: 2499868
PacketsExp: 21858
FlowsExp: 3381
Flow active timeout: 60
Flow inactive timeout: 15
Sampling interval: 1
Sampling algorithm: Deterministic sampling (1)
Padding: 00
Note the above sampled netflow data records include no FLOW data just some sort of summary.
The text was updated successfully, but these errors were encountered: