Linux and UNIX Man Pages

Linux & Unix Commands - Search Man Pages

flow-rpt2rrd(1) [debian man page]

flow-rpt2rrd(1) 					      General Commands Manual						   flow-rpt2rrd(1)

NAME
flow-rpt2rrd -- Convert flow-report CSV output to RRDtool format. SYNOPSIS
flow-rpt2rrd [-nv] [-d debug_level] [-k keys] [-K keys_file] [-f fields] [-p rrd_path] [-P rrd_postfix] [-r rrd_storage] DESCRIPTION
The flow-rpt2rrd utility processes the CSV output of flow-report into RRDtool format. The aggregates for a key are each stored as a DS in RRD filename {rrd_path,"/",key,rrd_postfix,".rrd"}. By default a DS is created for flows, octets, and packets. The key must be specified, for example an ip-port report could use smtp,nntp,ssh,telnet as the keys which would create a separate RRD for each key. OPTIONS
-d debug_level Set debug level to debug_level (debugging code) -h Help. -k keys|html Comma separated list of key values. If the report has symbols then the key must be the symbol, ie smtp not 25. The totals_* lines may be used if they are enabled in the report. There is no default, keys must be specified with -k or -K. -K keys_file Load keys from keys_file. See -k. -f Comma separated list of columns to store. Each column maps to a DS in the RRD. Defaults to flows,octets,packets -n Enable symbol table lookups. For example TCP port 25 = smtp. This will result in RRD file names with the symbolic names if sym- bol lookups were not enabled in the report. -p rrd_path Set path to RRD files. Defaults to ".". -P rrd_postfix Set RRD file name postfix. Defaults to "". -r rrd_storage Set RRD storage for 5 minute, 30 minute, 2 hour, and 1 day databases. List items are : seperated. Defaults to 600:600:600:732. -v Enable verbose output. EXAMPLES
The following example shows the combined use of flow-nfilter (inline), flow-report, and flow-rpt2rrd to create an RRD depicting traffic from clmbo-r4 to AS 10796 and 6478 for 2004-11-08. rrdtool graph is then used to create a .png. #!/bin/sh cat << EOF>report.cfg include-filter nfilter.cfg stat-report CLMBO-R4-TO-INTERNET-BY-DESTINATION-AS type destination-as filter CLMBO-R4-INTERNET-OUT scale 100 output options +header,+xheader fields -duration stat-definition 5min-summaries report CLMBO-R4-TO-INTERNET-BY-DESTINATION-AS EOF cat << EOF>nfilter.cfg # ifMIB.ifMIBObjects.ifXTable.ifXEntry.ifName.46 = so-0/0/0.0 filter-primitive CLMBO-R4-INTERNET type ifindex permit 46 # Match on traffic to the Internet filter-definition CLMBO-R4-INTERNET-OUT match output-interface CLMBO-R4-INTERNET EOF mkdir rrds # 5 minute flow files from flow-capture are here FLOW_DATA=/flows/clmbo-r4/2004-11-08/ # for each 5 minute flow,aggregate with flow-report then store to RRD for name in $FLOW_DATA/*; do echo working...$name flow-report -s report.cfg -S5min-summaries < $name | flow-rpt2rrd -k10796,6478 -p rrds done # first flow - 0:1:23 11/8/2004 START=1099890083 # last flow - 0:1:25 11/9/2004 END=1099976485 rrdtool graph CLMBO-R4-TO-INTERNET.png --start $START --end $END --vertical-label "Bits/Second" --title="CLMBO-R4 TO INTERNET BY AS" DEF:AS10796in=rrds/10796.rrd:octets:AVERAGE DEF:AS6478in=rrds/6478.rrd:octets:AVERAGE CDEF:b_AS10796in=AS10796in,8,* CDEF:b_AS6478in=AS6478in,8,* LINE1:b_AS10796in#FF0000:AS10796-in LINE1:b_AS6478in#555555:AS6478-in .fi BUGS
Hard coded to expect 5 minute flow file intervals. Does not properly parse flow-report time-series output. AUTHOR
Mark Fullmer maf@splintered.net SEE ALSO
flow-tools(1) flow-rpt2rrd(1)

Check Out this Related Man Page

flow-send(1)						      General Commands Manual						      flow-send(1)

NAME
flow-send -- Transmit flow data with the NetFlow protocol. SYNOPSIS
flow-send [-h] [-d debug_level] [-m privacy_mask] [-s] [-x xmit_delay] [-V pdu_version] localip/remoteip/port DESCRIPTION
The flow-send utility is used to transmit flows in NetFlow format to a collector specified by localip/remoteip/port. OPTIONS
-d debug_level Enable debugging. -h Display help. -s Enable spoofing of source IP address. -m privacy_mask Apply privacy_mask to the source and destination IP address of flows. For example a privacy_mask of 255.255.255.0 would convert flows with source/destination IP addresses 10.1.1.1 and 10.2.2.2 to 10.1.1.0 and 10.2.2.0 respectively. -V pdu_version Use pdu_version format when transmitting. 1 NetFlow version 1 (No sequence numbers, AS, or mask) 5 NetFlow version 5 6 NetFlow version 6 (5+ Encapsulation size) 7 NetFlow version 7 (Catalyst switches) 8.1 NetFlow AS Aggregation 8.2 NetFlow Proto Port Aggregation 8.3 NetFlow Source Prefix Aggregation 8.4 NetFlow Destination Prefix Aggregation 8.5 NetFlow Prefix Aggregation 8.6 NetFlow Destination (Catalyst switches) 8.7 NetFlow Source Destination (Catalyst switches) 8.8 NetFlow Full Flow (Catalyst switches) 8.9 NetFlow ToS AS Aggregation 8.10 NetFlow ToS Proto Port Aggregation 8.11 NetFlow ToS Source Prefix Aggregation 8.12 NetFlow ToS Destination Prefix Aggregation 8.13 NetFlow ToS Prefix Aggregation 8.14 NetFlow ToS Prefix Port Aggregation 1005 Flow-Tools tagged version 5 -x xmit_delay Configure a microsecond transmit delay between packets. This may be necessary in some configurations to prevent a transmit buf- fer overrun. EXAMPLES
Transmit all flows in the directory /flows/krc4 to the collector at 10.0.0.1 listening on port 9500. flow-cat /flows/krc4 | flow-send 0/10.0.0.1/9500 Generate a test pattern of version 7 flows and send them to a collector at 10.0.0.1 listening on port 9500. flow-gen -V7 | flow-send 0/10.0.0.1/9500 BUGS
It is not currently possible to convert between the aggregated formats (8.x) and the non aggregated formats (1,5,6,7). AUTHOR
Mark Fullmer maf@splintered.net SEE ALSO
flow-tools(1) flow-send(1)
Man Page