Rrd can archive various levels of detail depending on how you have it
configured.  There's a doc somewhere that explains what each level of
detail does includes.

The rrd "arbitrary graphs" feature is kinda clunky.  Half the data file
options don't actually exist.  Would be nice if there was a GUI or SQL
like interface to the rrd data.  Maybe there is and I don't about it?  

Gary


-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of
Aykut Demirkol
Sent: Monday, March 10, 2008 3:14 PM
To: [email protected]
Subject: Re: [Ntop] Correct way to store enormous Netflow data? Ip toIp
logging?

Yeah some TB.
Can RRD keep logs as  "Ip:port-Ip:port Date" format?
I thought it can just keep summary of overall traffic for graphical
representation..

Gary Gatten wrote:
> Your netflow data is 10GB / day?  That's a LOT of flow data - roughly
> equal to 10TB of actual data packets / network data a day.
>
> Rrd is one way to archive data.  The other is to dump the flow data
and
> archive it somehow.  I haven't checked, but I'm sure somewhere on the
> net someone has a tool to do this.  If not it wouldn't be all that
> difficult to build.
>
> The type of data you want should be available in rrd.  Play around a
> little and if you can't find it let me know.
>
> Gary
>
>
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf
Of
> Aykut Demirkol
> Sent: Monday, March 10, 2008 5:04 AM
> To: [email protected]
> Subject: [Ntop] Correct way to store enormous Netflow data? Ip to Ip
> logging?
>
> Hi,
> I am getting my Netflow data to Ntop. Can view and analyze the data
with
> out a problem.
> But I need to see "Source IP:Port - Destination IP:Port - Date" kind
of
> a log for past data.
> Secondly, my logs will be too big (It is taking 10G daily when using
> nfsen) and I may need to go past months logs and see connections log
for
> a specific date. What can be the best way of logging connections by
> ntop?
>
>
> Aykut Demirkol
> _______________________________________________
> Ntop mailing list
> [email protected]
> http://listgateway.unipi.it/mailman/listinfo/ntop
>
>
>
>
>
> <font size="1">
> <div style='border:none;border-bottom:double windowtext
2.25pt;padding:0in 0in 1.0pt 0in'>
> </div>
> "This email is intended to be reviewed by only the intended recipient
>  and may contain information that is privileged and/or confidential.
>  If you are not the intended recipient, you are hereby notified that
>  any review, use, dissemination, disclosure or copying of this email
>  and its attachments, if any, is strictly prohibited.  If you have
>  received this email in error, please immediately notify the sender by
>  return email and delete this email from your system."
>
> _______________________________________________
> Ntop mailing list
> [email protected]
> http://listgateway.unipi.it/mailman/listinfo/ntop
>
>   
_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop





<font size="1">
<div style='border:none;border-bottom:double windowtext 2.25pt;padding:0in 0in 
1.0pt 0in'>
</div>
"This email is intended to be reviewed by only the intended recipient
 and may contain information that is privileged and/or confidential.
 If you are not the intended recipient, you are hereby notified that
 any review, use, dissemination, disclosure or copying of this email
 and its attachments, if any, is strictly prohibited.  If you have
 received this email in error, please immediately notify the sender by
 return email and delete this email from your system."

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop

Reply via email to