Re: [Nfdump-discuss] Cut flows on specific time

2007-01-02 Thread Peter Haag
__ | Nfdump-discuss mailing list | [EMAIL PROTECTED] | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83

Re: [Nfdump-discuss] Feature request: read compressed formats

2007-01-03 Thread Peter Haag
uss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Limmatquai 138

Re: [Nfdump-discuss] [Nfsen-discuss] nfdump snapshot 20070110 and -R option

2007-01-25 Thread Peter Haag
> >Hi Peter, > > On Wed, 17 Jan 2007, at 09:11, Peter Haag wrote: > >> - --On January 16, 2007 17:39:57 + Maurizio Molina >> <[EMAIL PROTECTED]> wrote: >> >> | Hi, >> | the last nfdump snapshot (20070110) seems to have problems with

Re: [Nfdump-discuss] nfdump aggregation

2007-02-02 Thread Peter Haag
ss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Limmatquai 138, CH-8001 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web: http://www.switch.ch/ -BEGIN PGP SIGNATURE--

Re: [Nfdump-discuss] Configurable logging feature request

2007-02-22 Thread Peter Haag
&p=sourceforge&CID=DEVDEV | ___ | Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haa

Re: [Nfdump-discuss] Filters per sources

2007-02-26 Thread Peter Haag
share your | opinions on IT & business topics through brief surveys-and earn cash | http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV | ___ | Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https:/

Re: [Nfdump-discuss] Filters per sources

2007-02-26 Thread Peter Haag
info/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Limmatquai 138, CH-8001 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web

Re: [Nfdump-discuss] Multiple seperate filters in nfdump

2007-03-01 Thread Peter Haag
d, as not needed. - Peter | | Most likely there is a vastly superior 3rd option but I'm not sure what it is. | Any guidance would be much appreciated. | | Paul. - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fin

Re: [Nfdump-discuss] Multiple netflow sensors sending to one collector

2007-03-02 Thread Peter Haag
w.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV | ___ | Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education

Re: [Nfdump-discuss] Maniuplating output format

2007-04-13 Thread Peter Haag
EMAIL PROTECTED] | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Bo

Re: [Nfdump-discuss] nfdump java interface with JNI

2007-04-19 Thread Peter Haag
Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web: http://www.switch.ch/ -BEGIN PGP SIG

Re: [Nfdump-discuss] Logfile question

2007-04-30 Thread Peter Haag
| Quis custodiet ipsos custodes? | | | - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail:

Re: [Nfdump-discuss] Logfile question

2007-04-30 Thread Peter Haag
ic using tcpdump, which includes v9 template and data packets, I'll have a look into that. - Peter | | -Original Message----- | From: Peter Haag [mailto:[EMAIL PROTECTED] | Sent: Monday, April 30, 2007 8:50 AM | To: Stephen W. Bradley; nfdump-discuss@lists.sourceforge.net | Subject

Re: [Nfdump-discuss] nfdump compile issue when using --enable-nfprofile

2007-05-07 Thread Peter Haag
urceforge.net/powerbar/db2/ | ___ | Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerp

Re: [Nfdump-discuss] Discrepency in BPS when using nfcapd vs flow-capture

2007-05-10 Thread Peter Haag
ling list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC

Re: [Nfdump-discuss] Unable to Read .current Files Using nfdump-snapshot-20070312

2007-05-10 Thread Peter Haag
ss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Limmatquai 138, CH-8001 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web: http://www.s

Re: [Nfdump-discuss] Unable to Read .current Files Using nfdump-snapshot-20070312

2007-05-10 Thread Peter Haag
//lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Limmatquai 138, CH-8001 Zurich, Sw

Re: [Nfdump-discuss] Unable to Read .current Files Using nfdump-snapshot-20070312

2007-05-10 Thread Peter Haag
rge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Limmatquai 138, CH-8001 Zuric

Re: [Nfdump-discuss] sequence errors

2007-06-05 Thread Peter Haag
w. | http://sourceforge.net/powerbar/db2/ | ___ | Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Pet

Re: [Nfdump-discuss] Router interfaces

2007-07-16 Thread Peter Haag
info/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web: h

Re: [Nfdump-discuss] Strange entries in flow capture

2007-07-18 Thread Peter Haag
-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D

Re: [Nfdump-discuss] Strange entries in flow capture

2007-07-19 Thread Peter Haag
both streams to different ports and therefore different nfcapd processes. It's on the todo list to make nfcapd multi stream aware. - - --On July 18, 2007 13:56:36 +0100 Ras <[EMAIL PROTECTED]> wrote: | On 18/07/07, Peter Haag <[EMAIL PROTECTED]> wrote: | > This looks totally st

[Nfdump-discuss] NfSen 1.3b released

2007-07-19 Thread Peter Haag
netflow sources, and therefore contains flows with different sampling rates. For not delaying 1.3 any longer I decided to move it into next upgrade of NfSen, but I will address this feature next. Regards - Peter - -- ___ SWITCH - The Swiss Education and Research Network __ Peter

[Nfdump-discuss] NfSen 1.3b 20070720

2007-07-20 Thread Peter Haag
- -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web: http://www.switch.ch

Re: [Nfdump-discuss] Experiences with Netflow v9

2007-08-06 Thread Peter Haag
wnload your FREE copy of Splunk now >> http://get.splunk.com/ | ___ | Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education a

Re: [Nfdump-discuss] Compilation issues with Solaris 10

2007-08-07 Thread Peter Haag
Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95

Re: [Nfdump-discuss] nfsen syslog problem

2007-08-09 Thread Peter Haag
http://get.splunk.com/ | ___ | Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engin

Re: [Nfdump-discuss] nfsen syslog problem

2007-08-09 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - --On August 9, 2007 13:33:58 +0200 Xavier Fustero <[EMAIL PROTECTED]> wrote: | Hi Peter, | | | On dj, 2007-08-09 at 10:41 +0200, Peter Haag wrote: | > -BEGIN PGP SIGNED MESSAGE- | > Hash: SHA1 | > | > | > | > - -

Re: [Nfdump-discuss] Issue aggregating with dstip6/prefixlen

2007-08-10 Thread Peter Haag
ceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Swi

Re: [Nfdump-discuss] Error opening webpage

2007-08-10 Thread Peter Haag
rceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-

Re: [Nfdump-discuss] start nfsen

2007-08-16 Thread Peter Haag
> http://get.splunk.com/ | ___ | Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer,

Re: [Nfdump-discuss] Unable to compile nfdump-snapshot-20070808

2007-08-20 Thread Peter Haag
al/lib/librrd_th.la | /usr/local/lib/librrd_th.a | | Any ideas why this isn't working? | | Thanks, | | -- | Eric Cables - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA

Re: [Nfdump-discuss] nfdump filter "AS in [ ]"

2007-09-24 Thread Peter Haag
e.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-

Re: [Nfdump-discuss] Problem when installing

2007-09-24 Thread Peter Haag
iling list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWIT

Re: [Nfdump-discuss] incoming / outgoing interfaces not recorded in NFDUMP

2007-09-24 Thread Peter Haag
s, not web links. - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web: http

Re: [Nfdump-discuss] IP Ports

2007-10-11 Thread Peter Haag
cuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstras

Re: [Nfdump-discuss] IP Ports

2007-10-11 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Ralf, - --On October 11, 2007 2:33:37 PM +0200 Ralf Kleineisel <[EMAIL PROTECTED]> wrote: | Peter Haag wrote: | | > As for displaying I only partly agree: So far I find it very handy to have ICMP | > type/code directly displayed in

Re: [Nfdump-discuss] Lost flows

2007-10-12 Thread Peter Haag
w >> http://get.splunk.com/ | ___ | Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag

[Nfdump-discuss] nfdump-1.5.6 released

2007-10-15 Thread Peter Haag
compression ratio is about 50% in average but very fast, it is very well suited for nfdump. Existing files can be compressed using ../nfdump -j The file format is completely transparent. - Peter - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security

Re: [Nfdump-discuss] nfdump 1.5.6 compile problems

2007-10-25 Thread Peter Haag
| This SF.net email is sponsored by: Splunk Inc. | Still grepping through log files to find problems? Stop. | Now Search log events and configuration files using AJAX and a browser. | Download your FREE copy of Splunk now >> http://get.splunk.com/ |

Re: [Nfdump-discuss] Sequence failure

2007-11-01 Thread Peter Haag
he Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web: http://www.switch.ch/ -BEGIN PGP

Re: [Nfdump-discuss] [Nfsen-discuss] EST time change (1 hour back).......

2007-11-07 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Find appended the patch for nfdump-1.5.6 correcting the daylight saving bug. It's required if you work with data created during daylight saving time. - Peter - --On November 6, 2007 11:36:04 +0100 Peter Haag <[EMAIL PROTECTED]

Re: [Nfdump-discuss] Strange behaviour

2007-11-19 Thread Peter Haag
iss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web: http://www.switch.ch/ -BEGIN PGP SIGNA

Re: [Nfdump-discuss] x86_64 ?

2007-11-23 Thread Peter Haag
iscuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web

Re: [Nfdump-discuss] NFSEN again

2007-12-03 Thread Peter Haag
.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mai

Re: [Nfdump-discuss] nfcapd memory leak?

2007-12-14 Thread Peter Haag
- The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web: http://www.switch.ch/ -BEGIN PG

Re: [Nfdump-discuss] Adding a new filter primitive, org_id

2008-03-04 Thread Peter Haag
eforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-m

Re: [Nfdump-discuss] why nfdump don't use next hop field?

2008-03-05 Thread Peter Haag
ITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web: http://www.switch.ch/ -BEG

Re: [Nfdump-discuss] why nfdump don't use next hop field?

2008-03-13 Thread Peter Haag
far, as lot of the work as done in my free time. If you are willing to test an early adopter release, most likely including lots of bug - feel free to ping me in a few weeks. - Peter | | rgds. | | On Wed, Mar 5, 2008 at 8:00 PM, Peter Haag <[EMAIL PROTECTED]> wrote: | | > -BEGI

Re: [Nfdump-discuss] Adding a new filter primitive, org_id

2008-04-02 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - --On March 28, 2008 16:27:15 +0100 Vegard Vesterheim <[EMAIL PROTECTED]> wrote: | On Wed, 05 Mar 2008 08:46:25 +0100 Vegard Vesterheim <[EMAIL PROTECTED]> wrote: | | > On Tue, 04 Mar 2008 13:08:52 +0100 Peter Haag <[EMAIL

Re: [Nfdump-discuss] nfdump source code documentation

2008-04-14 Thread Peter Haag
/java.sun.com/javaone | ___ | Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer,

Re: [Nfdump-discuss] nfcapd and pf_ring and distributed collectors

2008-04-14 Thread Peter Haag
__ | Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 6

Re: [Nfdump-discuss] Implementation of overflow correction of SysUptime counter in netflow_v*.c

2008-06-28 Thread Peter Haag
urceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E

Re: [Nfdump-discuss] bash: syntax error near unexpected token `('

2008-07-04 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Bjoern Weiland wrote: | Nino Ciurleo wrote: |> try with: |> nfdump -r /and/dir/nfcapd.200407110845 -c 100 "proto tcp and ( src ip |> 172.16.17.18 or dst ip 172.16.17.19 )" | | That did it, thanks guys, simplest thing, actually. It works with single |

Re: [Nfdump-discuss] Implementation of overflow correction of SysUptime counter in netflow_v*.c

2008-07-05 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Daan, Daan van der Sanden wrote: | Hi, | | In both netflow_v5_v7.c and netflow_v9.c is an error in handling an overflow | of the SysUptime counter. However I can't test this it at the moment, because | I don't have any packet in which there is an o

Re: [Nfdump-discuss] change 1000 elements aggregate limit

2008-07-18 Thread Peter Haag
nywhere in the world | http://moblin-contest.org/redirect.php?banner_id=100&url=/ | ___ | Nfdump-discuss mailing list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Educatio

Re: [Nfdump-discuss] MiB, MB, ... prefixes in NFDUMP

2008-08-05 Thread Peter Haag
list | Nfdump-discuss@lists.sourceforge.net | https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC

Re: [Nfdump-discuss] MiB, MB, ... prefixes in NFDUMP

2008-08-05 Thread Peter Haag
snapshot has lot's of more v9 extensions - so stay tuned! It will be ready soon. - Peter | | best regards | Pavel | | * Peter Haag ([EMAIL PROTECTED]) wrote: |> Hi Pavel, |> |> Yes - this is a known issue. NfSen switched already to the 1000 scaling |> factors - nfdump up

[Nfdump-discuss] new nfdump snapshot

2008-08-15 Thread Peter Haag
s record ) does not yet show the additional tags. ** THIS RELEASE IS NOT INTENDED FOR PRODUCTION ** This release works with NfSen 1.3, however, the interface is not yet able to profit from the new options. - Peter - -- ___ SWITCH - The Swiss Education and Research Network __ Pe

[Nfdump-discuss] Nfdump for packeteer PacketShaper

2008-08-15 Thread Peter Haag
ITCH - The Swiss Education and Research Network ______ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web: http://www.switch.ch/ -BEGIN

[Nfdump-discuss] Nfdump for Cisco's ASA (adaptive security appliance)

2008-08-15 Thread Peter Haag
Peter - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: [EMAIL PROTECTED] Web:

Re: [Nfdump-discuss] nfcapd -E

2009-02-19 Thread Peter Haag
=2 > dOctets = 80 > > Thanks, > Tony - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2,

[Nfdump-discuss] nfdump 1.5.7 daylight saving patch

2009-03-03 Thread Peter Haag
when.tm_yday = 0; + when.tm_isdst = -1; if ( strlen(timestring) != 12 ) { LogError( "Wrong time format '%s'\n", timestring); I'm sorry for the trouble. - Peter - -- _______ SWITCH - The Swiss Education and Research Networ

Re: [Nfdump-discuss] schedule for next stable release?

2009-04-08 Thread Peter Haag
Environment. > Download a free trial of Rational Requirements Composer Now! > http://p.sf.net/sfu/www-ibm-com > ___ > Nfdump-discuss mailing list > Nfdump-discuss@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Sw

[Nfdump-discuss] Intermediate Releases NfSen 1.3.1/nfdump-1.5.8

2009-05-11 Thread Peter Haag
runs cleanly on all 64bit CPUs. A new nfdump snapshot with support for flexibel netflow (FNF) and sampling support should be uploaded by the end of next week. Regards - Peter - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Memb

Re: [Nfdump-discuss] nfdump config.status: WARNING: Makefile.in seems to ignore the --datarootdir setting

2009-05-12 Thread Peter Haag
--- > > -- > The NEW KODAK i700 Series Scanners deliver under ANY circumstances! Your > production scanning environment may not be a perfect world - but thanks to > Kodak, there's a perfect scanner to get the job done! With the NEW KODAK i700

Re: [Nfdump-discuss] Nfsen question

2009-06-17 Thread Peter Haag
s.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerla

Re: [Nfdump-discuss] nfcapd sees no netflow traffic?

2009-06-17 Thread Peter Haag
> > ___ > Nfdump-discuss mailing list > Nfdump-discuss@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter

Re: [Nfdump-discuss] Daylight Saving Time and nfcapd?

2009-06-18 Thread Peter Haag
e.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: pe

[Nfdump-discuss] nfdump 1.6b snapshot available

2009-06-19 Thread Peter Haag
mp-1.5.8 and can be used together with NfSen. However, not all new feature can be used as NfSen does not yet support them. Feedback is appreciated Happy playing! - Peter - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH

Re: [Nfdump-discuss] heapsort implementation in nfstat.c

2009-06-24 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Luis, Nice to hear from you! Yes - there is a reason for these changes. I will contact you off list, as this is not really something to bother all users here on the list. - Peter Luis Servin wrote: > Hi Peter, > > I have been looking

Re: [Nfdump-discuss] Nfdump - speed

2009-07-14 Thread Peter Haag
requires, which is the most influencing factor for speed. Memory can not be replaced except by memory! having enough memory an I.O capacity is the credo. Hope this helps - Peter - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH

Re: [Nfdump-discuss] nfcapd/nfdump Cross Platform Portability

2009-07-14 Thread Peter Haag
6 to x86_64 without troubles. Gruss - Peter > > > Thanks -- Till - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH,

Re: [Nfdump-discuss] Nfdump - speed

2009-07-14 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Jan Pazdera wrote: > Hi all, > snipp .. >> >> > I would like to add my experience with filtering of huge data amounts. A > year ago, we used 32b nfsen/nfdump on dual core cpu and 4 GB RAM with > RAID5 to collect data with 75k flows per second on 10G

Re: [Nfdump-discuss] Nfdump - speed

2009-07-15 Thread Peter Haag
read: 325280619 Sys: 47.950s flows/second: 112848.9 Wall: 48.285s flows/second: 112066.9 IP list Total flows processed: 5411216, Blocks skipped: 0, Bytes read: 325280619 Sys: 1.840s flows/second: 2940696.1 Wall: 1.857s flows/second: 2913259.3 - Peter > > On Tue, J

Re: [Nfdump-discuss] nfdump on solaris 10 core dumps

2009-07-30 Thread Peter Haag
Nfdump-discuss@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7

Re: [Nfdump-discuss] nfdump on solaris 10 core dumps

2009-07-31 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi John, John Kougoulos wrote: > Hello, > > sorry for this noise, 1.5.8 seems to work ok. however this is valid for > 1.6b, in case anyone is interested. The gdb output is from 1.6b snapshot > > Regards, > John After running configure, edit config

Re: [Nfdump-discuss] Re: How can display IP prefix

2009-08-03 Thread Peter Haag
- > > ___ > Nfdump-discuss mailing list > Nfdump-discuss@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Pete

Re: [Nfdump-discuss] Re: Re: How can displa y IP prefix

2009-08-04 Thread Peter Haag
> Eddie > > > > > > 寄件人﹕ Peter Haag > 收件人 Chor Keung Li > 副本(CC) nfdump-discuss@lists.sourceforge.net > 傳送日期﹕ 2009 年 8月 4 日 星期二 下午 1:28:12 > 主題: Re: [Nfdump-discuss] Re: How can display IP prefix > > -BEGIN PG

Re: [Nfdump-discuss] Re: Re: Re: How can display IP prefix

2009-08-04 Thread Peter Haag
gt; > Thanks again!! > > Eddie > > > > 寄件人﹕ Peter Haag > 收件人 Chor Keung Li > 副本(CC) nfdump-discuss@lists.sourceforge.net > 傳送日期﹕ 2009 年 8月 4 日 星期二 下午 3:53:59 > 主題: Re: Re: [Nfdump-discuss] Re: How can display IP prefix > > -BEGIN PGP SIGNED

Re: [Nfdump-discuss] Re: Re: Re: Re: H ow can display IP prefix

2009-08-04 Thread Peter Haag
I will think about that. - Peter > > Thank you so much for your reply!! > > Eddie > > > > ____ > 寄件人﹕ Peter Haag > 收件人 Chor Keung Li > 副本(CC) nfdump-discuss@lists.sourceforge.net > 傳送日期﹕ 2009 年 8月 4 日 星期二 下午 7:54:32 >

Re: [Nfdump-discuss] Wrong size and date time stamp with ASA using NFDUMP

2009-08-05 Thread Peter Haag
uss mailing list > Nfdump-discuss@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA

Re: [Nfdump-discuss] Wrong size and date time stamp with ASA using NFDUMP

2009-08-11 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Scott Dier wrote: > Peter Haag wrote: >> Be careful with ASA. 1.6b does not yet support ASA. There are lots of >> specials with that platform. You may download the >> nfdump-1.5.7-nsel tree, which supports ASA. The

Re: [Nfdump-discuss] nfdump on solaris 10 core dumps

2009-08-12 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Till Dörges wrote: > On 31.07.2009 07:34, Peter Haag wrote: >> John Kougoulos wrote: > >>> I have compiled nfdump in solaris 10/SPARC and everything works ok, but >>> when I use nfdump -R in specific directories

Re: [Nfdump-discuss] custom format, rawer data?

2009-09-25 Thread Peter Haag
ications to market and stay > ahead of the curve. Join us from November 9-12, 2009. Register now! > http://p.sf.net/sfu/devconf > ___ > Nfdump-discuss mailing list > Nfdump-discuss@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinf

[Nfdump-discuss] nfdump 1.6b snapshot available

2009-09-30 Thread Peter Haag
( legacy 1.4 compatibility ) o Make use of log (syslog) functions for nfprofile. o Move log functions to util.c Thanks - Peter - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95

Re: [Nfdump-discuss] sflow support

2009-10-06 Thread Peter Haag
> > ___ > Nfdump-discuss mailing list > Nfdump-discuss@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Securi

Re: [Nfdump-discuss] [Nfsen-discuss] nfdump 1.6b snapshot available

2009-11-03 Thread Peter Haag
: engine id 5, type 0, IP: x.x.x.x, Sampling Mode: 2, Sampling Interval: 128 I still take feedback from 1.6b testers for any issues found in 1.6b. Hope this helps. - Peter Szymon Trocha wrote: > Peter Haag pisze: >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA1 >> &

Re: [Nfdump-discuss] sfcapd / ndfump ip address backwards

2009-11-10 Thread Peter Haag
__ > Nfdump-discuss mailing list > Nfdump-discuss@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31

Re: [Nfdump-discuss] Nfdump Flow tag support

2009-11-16 Thread Peter Haag
_ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: peter.h...@switch.ch Web: http://www.switch.ch/

[Nfdump-discuss] sflow

2009-11-17 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Dear all, All those interested in testing sflow, please contact me off list. - Peter - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03

Re: [Nfdump-discuss] IPv6 aggregation woes in current nfdump snapshot

2009-11-19 Thread Peter Haag
> Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day > trial. Simplify your report design, integration and deployment - and focus on > what you do best, core application coding. Discover what's new wit

Re: [Nfdump-discuss] Nfdump Flow tag support

2009-11-23 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Onur Bektas wrote: > Hi Peter, > > On 11/17/2009 8:46 AM, Peter Haag wrote: > > > Onur BEKTAS wrote: > >>>> Hi all, >>>> >>>> Does nfdump has support for flow tagging ? (like flow-tag i

Re: [Nfdump-discuss] Regarding nfcapd.........

2009-11-24 Thread Peter Haag
lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH, Werdstrasse 2, P.O. Box, CH-8021 Zurich, Switzerland E-mail: peter.

Re: [Nfdump-discuss] Nfcapd Sampling Rates with run-length

2009-12-04 Thread Peter Haag
ferred sampling rate or would it be > possible to modify nfcapd to handle the run-rate? > > - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D D7 SWITCH,

Re: [Nfdump-discuss] Nfcapd Sampling Rates with run-length

2009-12-07 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Alistair Cockeram wrote: > On Fri, Dec 04, 2009 at 03:43:55PM +0100, Peter Haag wrote: >> I'm not aware of any fields, which export the run length. nfdump simply >> uses the sampling rate, which is announced the v5 header. In

Re: [Nfdump-discuss] Change name of sources?

2009-12-08 Thread Peter Haag
t > Nfdump-discuss@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/nfdump-discuss - -- ___ SWITCH - The Swiss Education and Research Network __ Peter Haag, Security Engineer, Member of SWITCH CERT PGP fingerprint: D9 31 D5 83 03 95 68 BA FB 84 CA 94 AB FC 5D

Re: [Nfdump-discuss] nfcapd segfault when not saving engine type/ID

2009-12-14 Thread Peter Haag
78122253, Sequence Errors: 0, Bad Packets: 0 > > The boxes get fed by Cisco Catalyst 6500 series, mostly running SXI* IOS > and exporting dual-stack netflow v9. > > Any ideas? The system is really old and there might just have been a > botched update in those 1000 days uptime t

Re: [Nfdump-discuss] nfcapd segfault when not saving engine type/ID

2009-12-14 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Disregard the last patch! It does not apply. Use the one appended on this mail. Sorry - Peter Peter Haag wrote: > Hi Bernhard, > Thanks for the bug report. It's a not initialized variable. How careless! > Find append

Re: [Nfdump-discuss] nfcapd segfault when not saving engine type/ID

2009-12-16 Thread Peter Haag
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Bernhard Schmidt wrote: > On Tue, Dec 15, 2009 at 08:26:26AM +0100, Peter Haag wrote: > >> Disregard the last patch! It does not apply. >> Use the one appended on this mail. > > Thanks, I've installed it, so far no c

  1   2   3   4   >