Flewton is an extensible Netflow collector.
Refer to the comments in the sample configuration shipped with Flewton.
In a nutshell:
java [options] -jar flewton.jarBy default, Flewton will search for its configuration file as /etc/flewton/flewton.cfg, /etc/flewton.cfg, and ./flewton.cfg, using the first one found. You can specify a path to your configuration using the flewton.config system property, for example:
java -Dflewton.config=/usr/local/etc/flewton.cfg -jar flewton.jarFlewton uses log4j for logging. By default, the log level is INFO and output is sent to stdout. To customize logging, create your own log4j.properties and set the log4j.configuration system property:
java -Dlog4j.configuration=file:///path/to/log4.props -jar flewton.jarBackends can be implemented in several languages. We currently support:
- Python
- Javascript
There are three ways you can tell Flewton about your external backends:
1. Place them in /etc/flewton.
2. Run flewton with -Dflewton.backend_path, placing your external backends in that directory.
3. Include your backends in the classpath so they can be loaded as resources by the classloader.
Identify your external backends in flewton.cfg by using their entire names, e.g.: js/my/AwesomeBackend.js or py/my/CoolerBackend.py. The default cfg that ships with flewton contains a few commented out examples, the source for which can also be found in the Flewton source code.
- Your class should extend
AbstractBackend. - Your class should have an
__init__method that accepts an instance ofHierarchicalConfiguration. - Module names must begin with ‘
py/’ to be properly identified as python. E.g.:py/my/module/path/Foo.py
- Your javascript should export two methods:
init(config)andwrite(record). The class types forconfigandrecordare the same as they would be in Java.
- Currently only Netflow v5 is supported, but additional Netflow formats are possible by implementing decoder classes as
com.rackspace.flewton.RecordvN(whereNis the version). Seecom.rackspace.flewton.Recordv5for an example. Patches welcome.
Flewton was developed by Gary Dusbabek and Eric Evans and made open-source by Rackspace.