Hi there,

I wonder how to mix bytes/packets filter and aggregation.

I want to do somthing like this :
        nfdump ... -b --filter="bytes > xxx"

and the result is not as expected. In fact I think that each
ticket is compared with the bytes filter before being aggregated.
And so the bidirectionnal flow printed does not show all bytes of
this session - but only shows the aggreation of tickets that was up to
xxx bytes.

Is there something I am doing wrong with my filter ? Is there any
solution to do this ?

Thanks for reading

Gabriel

------------------------------------------------------------------------------
Create and publish websites with WebMatrix
Use the most popular FREE web apps or write code yourself; 
WebMatrix provides all the features you need to develop and 
publish your website. http://p.sf.net/sfu/ms-webmatrix-sf
_______________________________________________
Nfdump-discuss mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/nfdump-discuss

Reply via email to