Re: [pmacct-discussion] effort to relicense pmacct from GPL to a BSD-style license

2020-01-08 Thread Aaron Finney
privately with me and/or Paolo. > > Kind regards, > > Job Snijders > > > DRAFT LIST OF KNOWN PMACCT AUTHORS (based on 'git shortlog -sen') > = > > Commits Author >2921 Paolo Lucent

Re: [pmacct-discussion] New Plugin Pull Request

2019-01-15 Thread Aaron Finney
#x27;d love to hear that > too! > > In any event, thank you for building and maintaining such a great tool. > > Will > > ___ > pmacct-discussion mailing list > http://www.pmacct.net/#mailinglists > -- *Aaron Finney*Infrastructure Engineering | OpenX 888 East Walnut Street, 2n

Re: [pmacct-discussion] Trying to collect NetFlow data from a Cisco router

2018-07-13 Thread Aaron Finney
And also post the netflow config section from your router. On Fri, Jul 13, 2018, 2:12 PM Kafui Akyea wrote: > I think you need to figure out if nfacctd is receiving any Netflow data at > all and if it is aggregating it first. > > So from a terminal do this > > # *nfacctd -l 2100* > > where 2100

Re: [pmacct-discussion] Geoloc lat/lon?

2018-06-05 Thread Aaron Finney
Answering myself...I went ahead and added it to my fork today. :) If there's any interest in a PR to merge back, I'd be happy to submit it. Cheers, Aaron On Mon, Jun 4, 2018 at 6:20 PM, Aaron Finney wrote: > Hi Paolo/all, > > Has anyone done (or planned) any work around

[pmacct-discussion] Geoloc lat/lon?

2018-06-04 Thread Aaron Finney
Hi Paolo/all, Has anyone done (or planned) any work around adding lat/lon data from geoipv2 as export primitives? As I understand it, only the country is currently available for exporting. We are adding lat/lon after the fact via etl, but it would be cleaner and more efficient to add it at the co

Re: [pmacct-discussion] pmacct 1.7.1 released !

2018-05-06 Thread Aaron Finney
Congratulations, Paolo, these are really great updates! Cheers, and thanks again for all of your hard work for the community. Aaron On Sun, May 6, 2018, 6:45 AM Paolo Lucente wrote: > VERSION. > 1.7.1 > > > DESCRIPTION. > pmacct is a small set of multi-purpose passive network monitoring tools.

Re: [pmacct-discussion] Capture DNS domain and HTTP destinations from incoming netflow packets

2018-02-19 Thread Aaron Finney
That's pretty vague. The info you're asking about is not exported via netflow, so you'll need some other process (i.e. ETLs, or stream processing if your pipeline's resources can handle it) to retrieve/match the additional data to your flow records - e.g. reverse DNS and mining aggregated HTTP serv

Re: [pmacct-discussion] How to differentiate Kafka "update" messages -- nfacctd, historic accounting, no nfacctd_time_new

2018-01-16 Thread Aaron Finney
If I understand the original question correctly, this is the same issue I was having writing to RiakTS; the records are considered immutable, so writing the same "key" (group of pmacct primitives) replaced the previous value. I solved this by adding the Kafka offset value of the first message proce

Re: [pmacct-discussion] Load balancing nfacctd

2017-09-05 Thread Aaron Finney
t have to go touch the router configs. > > > On Sep 5, 2017, at 11:35 AM, Aaron Finney wrote: > > I'm not sure I follow - do you mean setting up BGP peering of the > collectors to your source devices using the collector VIP as the neighbor > address? > > On Sep 5, 2

Re: [pmacct-discussion] Load balancing nfacctd

2017-09-05 Thread Aaron Finney
etflow? Interested in the solution below but would like to have BGP > aligned with netflow as well. > > On Sep 4, 2017, at 9:48 AM, Aaron Finney wrote: > > Great to hear, nice work! > > Aaron > > On Sep 4, 2017 1:55 AM, "Yann Belin" wrote: > > Hi all, >

Re: [pmacct-discussion] Load balancing nfacctd

2017-09-04 Thread Aaron Finney
ngth / ram usage). I'm still thinking about more advanced ways to check nfacctd health, if anyone has a suggestion. Cheers, Yann On Mon, Aug 21, 2017 at 4:02 PM, Aaron Finney wrote: > Hi Yann > > We use Consul for this, it works very well. > > https://www.consul.io > &g

Re: [pmacct-discussion] Load balancing nfacctd

2017-08-21 Thread Aaron Finney
Hi Yann We use Consul for this, it works very well. https://www.consul.io Aaron On Aug 21, 2017 6:44 AM, "Yann Belin" wrote: Hello, I have been looking into solutions to achieve reliable load balancing of my incoming flows across multiple nfacctd servers / daemons. Basic load balancing i

Re: [pmacct-discussion] Configuring pmacct/nfacctd as a Proxy/Ingest node & Visualize Data

2017-06-12 Thread Aaron Finney
I second Catalin's answer; once you have the data in Kafka, you can have multiple consumers working with it for different purposes. Our solution sends raw flow data to Kafka topics with a 24 hour retention time, then we have spark streaming jobs that do near-real-time processing for anomaly detecti

Re: [pmacct-discussion] Issues with Kafka/Avro sending schema to Kafka topic

2017-02-17 Thread Aaron Finney
gt; > Hi Aaron, > > The feature is post 1.6.1. Can you please switch to master code on GitHub? > > Thanks, > Paolo > > On Thu, Feb 16, 2017 at 10:44:23AM -0800, Aaron Finney wrote: > > Hi Paolo/all, > > > > I've been unable to get nfacctd to send the Avro

[pmacct-discussion] Issues with Kafka/Avro sending schema to Kafka topic

2017-02-16 Thread Aaron Finney
Hi Paolo/all, I've been unable to get nfacctd to send the Avro schema to a Kafka topic - I receive the following message when starting nfacctd: WARN: [/etc/nfacctd.conf:14] Unknown key: kafka_avro_schema_topic. Ignored. WARN: [/etc/nfacctd.conf:15] Unknown key: kafka_avro_schema_refresh_time. Ign

Re: [pmacct-discussion] nfacctd aggregate_filters not working correctly when defined in the same config file

2017-01-22 Thread Aaron Finney
olo > > On Sat, Jan 21, 2017 at 09:09:25AM -0800, Aaron Finney wrote: > > Hi Paolo, > > > > It's version 1.6.1: > > > > NetFlow Accounting Daemon, nfacctd 1.6.1 (20161001-00+c5). > > > > Thanks, > > > > Aaron > > > > >

Re: [pmacct-discussion] nfacctd aggregate_filters not working correctly when defined in the same config file

2017-01-21 Thread Aaron Finney
ably) master code on GitHub - can you please try > and confirm you experience the same with any of these? > > Paolo > > On Fri, Jan 20, 2017 at 07:03:15PM -0800, Aaron Finney wrote: > > Hello all, > > > > I promise I searched the archives exhaustively first... >

[pmacct-discussion] nfacctd aggregate_filters not working correctly when defined in the same config file

2017-01-20 Thread Aaron Finney
Hello all, I promise I searched the archives exhaustively first... We are trying to separate external ingress/egress traffic using aggregate_filter (config below), but it's not working as expected. When we only have one of the sections active and (xv_ext_in OR xv_ext_out) and comment out the oth