Hi,
I am having a problem with nfacctd getting way behind with ver 1.5.3
Everything is ok until I add a server that is sending a lot of netflows
then things start bogging down. I see the nfacctd plugins using 100% cpu using
top.
Then I start getting seg faults:
Nov 8 15:28:01 netflow2 kernel:
That is exactly what I had done!
On 8 Nov 2016 10:17 pm, "Paolo Lucente" wrote:
>
> Hi Cameron,
>
> Is it possible you restarted pmacct using pmacctd instead of nfacctd?
> Your description of what is happening would match 100% with that.
>
> Cheers,
> Paolo
>
> On Tue, Nov 08,
Hi Cedric,
0x3FFF (1073741823) is used to indicate packets that never enter or
exit the probe, ie. originated from or delivered to it. This is not
necessarily true since you use pmacctd and miss sfprobe_direction and
sfprobe_ifindex as part of your config. Please look at QUICKSTART doc
Hi Cameron,
Is it possible you restarted pmacct using pmacctd instead of nfacctd?
Your description of what is happening would match 100% with that.
Cheers,
Paolo
On Tue, Nov 08, 2016 at 01:53:59PM +1000, Cameron Murray wrote:
> Further to this it does appear that it is only recordings data
Hi Stephen,
If you do not filter over tags, ie. pre_tag_filter is not part of your
config, then all will make to the database and those packets coming from
a unit not in pretag.map will have a tag of zero. In other words both
behaviours are possible (all make to the DB or filter things you are