On Feb 12, "To [EMAIL PROTECTED]" wrote: > > That's basically all I can do for you. If it's truly important to you, > > contact me off-list and let's discuss paid support. > > This info was just what I was looking for to get me started. I'll let you > know what I come up with. Thanks again for the help.
I figured out that it was indeed "invalid" sflow packets. Apparently, sflow sends COUNTERSAMPLE and FLOWSAMPLE packets. COUNTERSAMPLE packets give a quick look at interface counters on the machine, whereas FLOWSAMPLE packets are actual packet fragments from IP connections. Ntop seems to simply parse, debug_print, and discard COUNTERSAMPLE packets...which made it confusing to look at the debug output and say "wow, lots of sflow coming in!" when in fact it was just for show, as Burton suggested. I added more switches (with active connections) to the switches sending sflow packets and I now have hosts with pretty graphs. Anyway, thanks for the help and sorry for the noise. Trapped in a dungeon of my own dumbassness, Mike _______________________________________________ Ntop mailing list [EMAIL PROTECTED] http://listgateway.unipi.it/mailman/listinfo/ntop
