Jakub- I too have noticed this, with Netflow v9 export from the CRS. But I don't think it is platform specific....
I collect at 1:1500 on the CRS. When I force nfcapd to ignore the sample rate exported by the router (using the -S 1 switch) the sampled values are correct, as output by nfdump. I then later apply the math (x 1500) and get the correct values in the post-processed data. We're not the first to notice this, and it would be really nice if we could track this down and fix it. See: http://sourceforge.net/tracker/?func=detail&atid=683752&aid=3427615&group_id=119350 for a similar issue, I commented on this bug at the bottom of the thread. Dave On Mon, Oct 1, 2012 at 6:14 AM, Jakub Słociński <[email protected]> wrote: > > So, in summary: > a) data seems to be gathered in a proper way > b) summary counters from nfcapd works well (those put into syslog each > rotation) > c) all other displayed data have crappy bytes/pkts couters. > > How can I check if data is stored properly and this is only presentation > layer bug? Data counters are 64bit long. > BTW. setup_translation_table fills proper elements (NF9_IN_BYTES). ------------------------------------------------------------------------------ Got visibility? Most devs has no idea what their production app looks like. Find out how fast your code is with AppDynamics Lite. http://ad.doubleclick.net/clk;262219671;13503038;y? http://info.appdynamics.com/FreeJavaPerformanceDownload.html _______________________________________________ Nfdump-discuss mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/nfdump-discuss
