Helly everybody, 

we want to set up IP based accountig for a students network. All hosts (> 
5.000) have static IP adresses, so PMACCT seems to be the right software to use!
To get started and understand sflow and pmacct I'm using a small lab 
environment with one laptop connected to a HP switch. sflow is enabled at the 
switch access port (laptop). 
Now I'd like to have 2 mysql tables (in/out) aggregating the consumed bandwith 
per IP on a hourly base.

Here the pmacct config I am using so far:
daemonize: true
interface: ens160
sfacctd_port: 6343

aggregate[in]: dst_host
aggregate[out]: src_host
!aggregate_filter[in]: dst net
!aggregate_filter[out]: vlan and src net

plugins: mysql[in], mysql[out]
sql_history: 1h
sql_history_roundoff: h
sql_host: localhost
sql_db: pmacct
sql_table_version: 6
sql_passwd: ****
sql_user: ****
sql_refresh_time: 60
sql_table [in]: acct_v6_in
sql_table [out]: acct_v6_out

sfacctd_renormalize: true
logfile: /home/administrator/sfacctd.log

I made 2 screenshots of the 2 mysql tables (in/out) with samples from the above 
config and to be able to go more in depth I attached a packet capture as well.

Now I actually want pmacct to only aggregate packets from and to my laptop 
( I thought aggregate_filter would be the right way to go, but 
when I remove the comments, pmacct 
will not write any samples to the database. It seems like everything gets 
filtered when going with the filters. Am I missing something?

Thanks a lot in advance!

pmacct-discussion mailing list

Reply via email to