I found you have to build the tables with timestamps and then when you
aggregate with timestamp_start and timestamp_end you can get the individual
flow records as opposed to aggregating the records.

Robert Juric



On Tue, Apr 19, 2016 at 9:00 AM, Dariush Marsh-Mossadeghi <
dari...@gravitas.co.uk> wrote:

> Hi List,
>
> Is there a way to get pmacctd/nfacctd to NOT do any aggregation of flow
> records ?
>
> Specifically,  I’ve got IPFIX coming off a router being handed by nfacctd
> and it would be useful to temporarily have visibility of every flow record.
> Tcpdump is not a suitable as part of what I’m trying to ascertain is
> whether the IPFIX data is accurate.
>
> Any suggestions/recipes/config snippets/pointers to RTFM would be
> gratefully received.
>
> Thanks
> Dariush
>
> Dariush Marsh-Mossadeghi
> E: dari...@gravitas.co.uk
> M: +44 7973 259510
> W: https://uk.linkedin.com/in/dariushmm
>
>
> _______________________________________________
> pmacct-discussion mailing list
> http://www.pmacct.net/#mailinglists
>
_______________________________________________
pmacct-discussion mailing list
http://www.pmacct.net/#mailinglists

Reply via email to