On 7/7/11 2:06 PM, Ricardo Rojo Bonfim wrote:
> hello everybody, I'm with problems to understand the nfcapd file..
> extension maps are always after the block header?
> it's about a configuration or is the standard?
> nfcapd has a limit of extension maps?

The file format is documented in nffile.h. There you will find MAX_EXTENSIONS
There is no fix order required for extension maps beside the fact, that a map
must always come before the first record requiring the extension map.

        - Peter

> 
> sorry for bad english
> 
> 
> 
> 
> ------------------------------------------------------------------------------
> All of the data generated in your IT infrastructure is seriously valuable.
> Why? It contains a definitive record of application performance, security 
> threats, fraudulent activity, and more. Splunk takes this data and makes 
> sense of it. IT sense. And common sense.
> http://p.sf.net/sfu/splunk-d2d-c2
> 
> 
> 
> _______________________________________________
> Nfdump-discuss mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/nfdump-discuss

-- 
Be nice to your netflow data. Use NfSen and nfdump :)

------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security 
threats, fraudulent activity, and more. Splunk takes this data and makes 
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2d-c2
_______________________________________________
Nfdump-discuss mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/nfdump-discuss

Reply via email to