📄 todo
字号:
FT_RECGET -> FTIO_RECGET - use ftio offsets.fts3rec_compute_offsets() could be done automatically on ftio_open(4READ) -- update everything to use ftio->fo.flow-split, flow-report timing problem when a period passes with no clock.source spoofing in flow-fanout is not going to work properly with multiplesources - need per source sequence numbers on output side.source spoofing - in flow-send use the exporter IP from the flow record.SCTP supportNetFlow v9 supportflow-rptfmtSparc/Linux portabilityhttp://www.debian.org/ports/sparc/ has a little more as doeshttp://www.ultralinux.org/http://www.auroralinux.org/Matt.Foster@Unilever.com> stat-report report1> input> time yesterday> path /data/%Y/%Y-%m/%Y-%m-%d/(dynamic path)filter actions invoke tags invoke tag-mask invoke privacy maskflow-capture - use ftfil ACL for accepting flows.flow-split should fail more gracefully when splitting on time with oldflow files without clocking information.flow-cat -> ftlib so flow-xxx /flows/data/2002 will work without using flow-catflow-probeflow-capture / flow-expire not removing empty directories.flow-report per src/dst tag src/dst host countreference ip2hostname utility on web pageflow-report, flow-nfilter, flow-tag - config file from command line string.flow-print strftime style processing.flow-cat mmap causes crash problem on Solariscisco magic filterstotal_flows should always be a u_int64, not u_int32DEC portability - check for snprintfRobin's libcap/flow-import patchflow-capture/flow-receive finish the locip/remip/port code to accept multiple exportersthe as substitution can be smarter, ie don't do substitution for multicasttraffic or output ifIndex 0, or possibly if the mask bits are 0.mmap should be turned off for large files since it won't work.directio md5 checksumsftio_write could use write() instead of writen() to better utilize d_bufwhen write() returns 0 -- ie on a TCP connection.flow-xlate - split overflow scaled flowsflow-bidirflow-import/export - argus filesflow-import/export - OCxmon filesflow-import/export - netramet filesflow-import/export - cabletron filesbgp integration - community (xxx:yyy) -> tag yyypacket sampling rate need to be stored in the flow file. flow-stat wouldneed to use this to estimate total # of flows--with-cflow - automagically build Dave's Cflow moduleflow-cat -R ifalias Reset ifalias -R ifmap Reset ifmap -L ifalias Load ifalias -L ifmap Load ifmap -S <path> where to look for symbol names -I <iplist> only load for IP'sflow-capture -M <path> where to look for symbol namessymbol file: ifmap exporter=1.2.3.4 ifIndex=99 name=FastEthernet0/0 encap=60 sample_rate=100 ifalias exporter=1.2.3.4 name=outside ifIndex_list=5,1,2,3,4,5flow-topflow-capture ager is running on all errorsincorporate flow-sortAC_ARG_WITH(socks,[ --with-libwrap use the libwrap library],[AC_DEFINE(HAVE_LIBWRAP)])instrument read/write for compression stats by using total_in and total_outflow-5to8 - convert v5 to v8 flowsflow-active maintains active src or destination IP address first/last seen on disk first_time last_time flows octets packetsregression testsflow-dns -l level (heirachy level, 0 is infinity) - level 1 would only be top level domains (.com, .edu, .net) - level 2 would be second level (ohio-state.edu, psu.edu, cic.net) - level 0 would be any level, ie FQDN's (shattered.net.ohio-state.edu)flow-reduce various data reducations glue together TCP connectionskeep state when there's a ftp control connection, then use thatto give hints about ftp data connections
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -