Hi Paolo,

Thanks for your reply. As requested, I've sent you capture of the sampled Ethernet sFlow datagrams. Let me know if you need any further info or captures.

Regards,
Daniel Swarbrick

On 30/12/12 20:55, Paolo Lucente wrote:
Hi Daniel,

I'd be happy to reproduce in lab and add the feature, like you say it
does not appear to be a biggie. Can you please send privately a capture,
full length, in pcap format of the sFlow datagrams (not containing the
workaround)?

Cheers,
Paolo

On Tue, Dec 25, 2012 at 08:19:47PM +0100, Daniel Swarbrick wrote:
Hi,

I'm evaluating sfacctd as an sFlow collector, with the intention of
sending sampled Ethernet flows to it from an in-house developed sFlow
agent.

I've noticed that our database is showing accumulated frame/packet
counts, but the byte counters are always zero.Examining the sfacctd
source code, I see that the frame length sent in the sampled Ethernet
flow is processed, but discarded. This seems like a fairly minor
oversight, whose functionality should be easy to add. Was this omitted
intentionally?

Our situation requires that we aggregate by source MAC address, so
sampled IPv4 flows are unsuitable. I have worked around the missing
functionality in the meantime by modifying our sFlow agent to send
reconstructed, sampled packet headers, containing just the source/dest
MAC address fields of the Ethernet frame, and the original frame length
included it the flow record. This is giving us frame counts and byte
counts in the database.

Daniel Swarbrick

_______________________________________________
pmacct-discussion mailing list
http://www.pmacct.net/#mailinglists
_______________________________________________
pmacct-discussion mailing list
http://www.pmacct.net/#mailinglists


_______________________________________________
pmacct-discussion mailing list
http://www.pmacct.net/#mailinglists

Reply via email to