Hi Steve,


On Fri, Jul 17, 2015 at 07:36:31AM -0400, Steve Clark wrote:

> Am I not able to simply put something like:
> interface: p4p1
> aggregate: src_host, dst_host, src_port, dst_port, proto, tos, in_iface, 
> out_iface
> plugins: nfprobe[p4p1]
> nfprobe_receiver:
> nfprobe_version: 9
> nfprobe_ifindex[p4p1]: 4
> in my config file?

Yes, just set nfprobe_direction to 'in' or 'out' and you should
start seeing interfaces populated. I'm afraid without something
dynamic based on a map you may hit a conceptual issue since you
should be capturing both directions of traffic. 

> I tried to use a pre-tag filter like
> nfprobe_ifindex[p4p1]: tag
> pre_tag_map: ./my.pretag.map
> then edited my.pretag.map as follows:
> set_tag=4 filter='net'

Again, nfprobe_direction is missing. nfprobe_ifindex is in
addition to nfprobe_direction but i reckon the documentation in
QUICKSTART may be confusing and definitiely it misses an example
where all the pieces are put together (will fix this asap). So
imagine you have prefix X.X.X.X connected on interface 10 and
Y.Y.Y.Y connected on interface 20, this should be the config:

nfprobe_direction: tag
nfprobe_ifindex: tag2
pre_tag_map: /path/to/pretag.map

Then in pretag.map:

set_tag=1       filter='src net X.X.X.X' jeq=eval_ifindex
set_tag=2       filter='dst net X.X.X.X' jeq=eval_ifindex
set_tag=1       filter='src net Y.Y.Y.Y' jeq=eval_ifindex
set_tag=2       filter='dst net Y.Y.Y.Y' jeq=eval_ifindex
set_tag=999     filter='net'

set_tag2=10     filter='src net X.X.X.X' label=eval_ifindex
set_tag2=10     filter='dst net X.X.X.X'
set_tag2=20     filter='src net Y.Y.Y.Y'
set_tag2=20     filter='dst net Y.Y.Y.Y'


pmacct-discussion mailing list

Reply via email to