Hi Daniel,

I'd be happy to reproduce in lab and add the feature, like you say it
does not appear to be a biggie. Can you please send privately a capture,
full length, in pcap format of the sFlow datagrams (not containing the
workaround)? 

Cheers,
Paolo

On Tue, Dec 25, 2012 at 08:19:47PM +0100, Daniel Swarbrick wrote:
> Hi,
>
> I'm evaluating sfacctd as an sFlow collector, with the intention of  
> sending sampled Ethernet flows to it from an in-house developed sFlow 
> agent.
>
> I've noticed that our database is showing accumulated frame/packet  
> counts, but the byte counters are always zero.Examining the sfacctd  
> source code, I see that the frame length sent in the sampled Ethernet  
> flow is processed, but discarded. This seems like a fairly minor  
> oversight, whose functionality should be easy to add. Was this omitted  
> intentionally?
>
> Our situation requires that we aggregate by source MAC address, so  
> sampled IPv4 flows are unsuitable. I have worked around the missing  
> functionality in the meantime by modifying our sFlow agent to send  
> reconstructed, sampled packet headers, containing just the source/dest  
> MAC address fields of the Ethernet frame, and the original frame length  
> included it the flow record. This is giving us frame counts and byte  
> counts in the database.
>
> Daniel Swarbrick
>
> _______________________________________________
> pmacct-discussion mailing list
> http://www.pmacct.net/#mailinglists

_______________________________________________
pmacct-discussion mailing list
http://www.pmacct.net/#mailinglists

Reply via email to