Sam Tetherow wrote: > I use nfcapd (part of nfdump) to capture the data, and have been using a > few of my own scripts to process the data. Not doing anything fancy > right now, just extracting data by IP address so I can graph user usage.
Ooh, that tickles my shell scripting fancy. ;) How much disk and CPU space is that using for you, and how much throughput are you tracking flows for? I know that Netflow only has to keep some basic information on the packet, not the whole packet itself, but even headers on my 20Mbps (peak) network could add up. (Also, how far back do you keep flow data? Obviously, if you're only keeping a week's worth, that's not as resource-intensive as a month, and so on.) David Smith MVN.net -- WISPA Wireless List: wireless@wispa.org Subscribe/Unsubscribe: http://lists.wispa.org/mailman/listinfo/wireless Archives: http://lists.wispa.org/pipermail/wireless/