This is not an nfcapd/nfdump issue, just a general question regarding
netflow times.

About 9 days ago we started receiving netflow data from a customer's
FortiGate firewall. At that time, the date/times in the flows were about 12
days in the past. I have confirmed the "bad" times exist in the incoming
raw packets. Over the next 8 days, the date/times were catching up to the
current time, and then they started moving into the future, where currently
they're about 2 days into the future and getting worse.

My question is, has anyone seen behavior like this before?

-- 
Ken Adey



CyGlass, Inc. is a wholly-owned subsidiary of Nominet UK. Nominet UK is
registered in England and Wales No. 3203859


This message is intended exclusively for the individual(s) to whom it is
addressed and may contain information that is privileged, or confidential.
If you are not the addressee, you must not read, use or disclose the
contents of this e-mail. If you receive this e-mail in error, please advise
us immediately and delete the e-mail. CyGlass, Inc. has taken every
reasonable precaution to ensure that any attachment to this e-mail has been
swept for viruses. However, Nominet cannot accept liability for any damage
sustained as a result of software viruses and would advise that you carry
out your own virus checks before opening any attachment
_______________________________________________
Nfdump-discuss mailing list
Nfdump-discuss@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfdump-discuss

Reply via email to