Hi there,
I wonder how to mix bytes/packets filter and aggregation.
I want to do somthing like this :
nfdump ... -b --filter="bytes > xxx"
and the result is not as expected. In fact I think that each
ticket is compared with the bytes filter before being aggregated.
And so the bidirectionnal flow printed does not show all bytes of
this session - but only shows the aggreation of tickets that was up to
xxx bytes.
Is there something I am doing wrong with my filter ? Is there any
solution to do this ?
Thanks for reading
Gabriel
------------------------------------------------------------------------------
Create and publish websites with WebMatrix
Use the most popular FREE web apps or write code yourself;
WebMatrix provides all the features you need to develop and
publish your website. http://p.sf.net/sfu/ms-webmatrix-sf
_______________________________________________
Nfdump-discuss mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/nfdump-discuss