flowdumper and Full Flow Information

Although flowdumper is generally less useful than flow-print, it has some unique features. You've already used the summary feature (-s) to test Cflow.pm. (flowdumper can also accept Perl instructions on the command line, but if you're sufficiently skilled in Perl to do that, you can read the flowdumper manual page.)

If you don't use the summary feature, flowdumper prints all the information the flow file includes for every flow.

# flowdumper ft-* FLOW index: 0xc7ffff ❶ router: 192.0.2.12 ❷ src IP: 158.43.128.72 dst IP: 192.0.2.37 input ifIndex: 9 output ifIndex: 1 src port: 53 dst port: 34095 pkts: 1 bytes: 130 ❸ IP nexthop: 192.0.2.37 start time: Sat Dec 31 23:54:42 2011 end time: Sat Dec 31 23:54:42 2011 protocol: ...

Get Network Flow Analysis now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.