* Matt Hamilton <ma...@netsight.co.uk> [2013-09-10 12:30]: > sven falempin <sven.falempin <at> gmail.com> writes: [nonsense deleted]
> The problem is that (I believe) that the pflow packet is not generated until > the state expires from pf. In the case of the scp transfer I saw that was not > for several days. Meaning I had no accounting/reporting of this data > transfer until it ended and the state expired. correct. > At which point the entire > data transferred during that state's life was counted as if it happened now. This I'd call a visualization bug; but that doesn't change too much here. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services GmbH, http://bsws.de, Full-Service ISP Secure Hosting, Mail and DNS Services. Dedicated Servers, Root to Fully Managed Henning Brauer Consulting, http://henningbrauer.com/