⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 flow-capture.1.in

📁 netflow,抓包
💻 IN
字号:
...\" $Header: /usr/src/docbook-to-man/cmd/RCS/docbook-to-man.sh,v 1.3 1996/06/17 03:36:49 fld Exp $...\"...\"	transcript compatibility for postscript use....\"...\"	synopsis:  .P! <file.ps>...\".de P!\\&..fl			\" force out current output buffer\\!%PB\\!/showpage{}def...\" the following is from Ken Flowers -- it prevents dictionary overflows\\!/tempdict 200 dict def tempdict begin.fl			\" prolog.sy cat \\$1\" bring in postscript file...\" the following line matches the tempdict above\\!end % tempdict %\\!PE\\!..sp \\$2u	\" move below the image...de pF.ie     \\*(f1 .ds f1 \\n(.f.el .ie \\*(f2 .ds f2 \\n(.f.el .ie \\*(f3 .ds f3 \\n(.f.el .ie \\*(f4 .ds f4 \\n(.f.el .tm ? font overflow.ft \\$1...de fP.ie     !\\*(f4 \{\.	ft \\*(f4.	ds f4\"'	br \}.el .ie !\\*(f3 \{\.	ft \\*(f3.	ds f3\"'	br \}.el .ie !\\*(f2 \{\.	ft \\*(f2.	ds f2\"'	br \}.el .ie !\\*(f1 \{\.	ft \\*(f1.	ds f1\"'	br \}.el .tm ? font underflow...ds f1\".ds f2\".ds f3\".ds f4\".ta 8n 16n 24n 32n 40n 48n 56n 64n 72n .TH "\fBflow-capture\fP" "1".SH "NAME"\fBflow-capture\fP \(em Manage storage of flow file archives by expiring old data\&..SH "SYNOPSIS".PP\fBflow-capture\fP [-h]  [-A\fI AS0_substitution\fP]  [-b\fI big|little\fP]  [-C\fI comment\fP]  [-c\fI flow_clients\fP]  [-d\fI debug_level\fP]  [-D\fI daemonize\fP]  [-e\fI expire_count\fP]  [-f\fI filter_fname\fP]  [-F\fI filter_definition\fP]  [-E\fI expire_size\fP]  [-m\fI privacy_mask\fP]  [-n\fI rotations\fP]  [-N\fI nesting_level\fP]  [-p\fI pidfile\fP]  [-R\fI rotate_program\fP]  [-S\fI stat_interval\fP]  [-t\fI tag_fname\fP]  [-T\fI active_def\fP|\fIactive_def,active_def\fP \&...]  [-V\fI pdu_version\fP]  [-z\fI z_level\fP] -w\fI workdir\fP \fIlocalip/remoteip/port\fP .SH "DESCRIPTION".PPThe \fBflow-capture\fP utility will receive and storeNetFlow exports to disk\&.  The flow files are rotated \fIrotations\fPtimes per dayand expiration of old flow files can be configured by number of filesor total space utilization\&.  Files are stored in \fBworkdir\fP and can optionally be stored in additional levels of directories\&.  Activefiles created by \fBflow-capture\fP beginwith \&'tmp\&'\&.  Files that are complete begin with \&'ft\&'\&..PPWhen the \fIremoteip\fP is configured only flowsfrom that exporter will be processed, this is the most secure and recommendedconfiguration\&.  When the \fIlocalip\fP is configured\fBflow-capture\fP will only process flowssent to the \fI localip\fP IP address\&.  If\fIremoteip\fP is 0 (not configured) flows from anysource IP address are accepted\&.  Multiple non aggregated PDU versions maybe accepted at once to support Cisco\&'s Catalyst 6500 NetFlowimplementation which exports from both the supervisor and MSFC with thesame IP address and same port but different export versions\&.  In this casethe exports will be stored in the format specified by \fIpdu_version\fP or whichever export type is received first\&..PPNetFlow exports are UDP and do not employ congestion control or aretransmission mechanism\&.  If the server flow-capture is configuredon is too busy, or the network is congested or lossy NetFlow exports willbe lost\&.  An estimate of lost flows is recorded in the flow files, andlogged via syslog\&.  Most servers will provide a count of dropped packetsdue to full socket buffers via the \fBnetstat\fP utility\&.For example \fBnetstat -s | grep full\fP will provide a countof UDP packets dropped due to full socket buffers\&.  If this is a persistentoccurrence either \fBflow-capture\fP will need a larger serveror the compression level should be decreased with -z\&..PPA SIGHUP signal will cause \fBflow-capture\fP to closethe current file and create a new one\&..PPA SIGQUIT signal will cause \fBflow-capture\fP to closethe current file and exit\&..SH "OPTIONS".IP "-A\fI AS0_substitution\fP" 10Cisco\&'s NetFlow exports represent the local autonomous system as 0 instead ofthe real value\&.  This option can be used to replace the 0 in the export withthe a configured value\&.  Unfortunately under certain configurations AS 0 canalso represent a cache miss or non forwarded traffic so use with caution\&..IP "-b\fI big\fP|\fIlittle\fP" 10Byte order of output\&..IP "-c\fI flow_clients\fP" 10Enable \fIflow_clients\fP TCP clients\&.  When libwrapis available the client must be in a permit list for the serviceflow-capture-client\&..IP "-C\fI Comment\fP" 10Add a comment\&..IP "-d\fI debug_level\fP" 10Enable debugging\&..IP "-e\fI expire_count\fP" 10Retain the maximum number of files so that the total file count isless than \fIexpire_count\fP\&.  Defaults to0 (do not expire)\&..IP "-E\fI expire_size\fP" 10Retain the maximum number of files so that the total storage is lessthan \fIexpire_size\fP\&.  The letters b,K,M,G canbe used as multipliers, ie 16 Megabytes is 16M\&.  Default to 0 (do not expire)\&..IP "-f\fI filter_fname\fP" 10Filter list filename\&.  Defaults to \fB@localstatedir@/cfg/filter\fP\&..IP "-F\fI filter_definition\fP" 10Select the active definition\&.  Defaults to default\&..IP "-h" 10Display help\&..IP "-m\fI privacy_mask\fP" 10Apply \fIprivacy_mask\fP to the source and destination IPaddress of flows\&.  For example a privacy_mask of 255\&.255\&.255\&.0 would convertflows with source/destination IP addresses 10\&.1\&.1\&.1 and 10\&.2\&.2\&.2 to 10\&.1\&.1\&.0and 10\&.2\&.2\&.0 respectively\&..IP "-n\fI rotations\fP" 10Configure the number of times flow-capture will create a new file per day\&.The default is 95, or every 15 minutes\&..IP "-N\fI nesting_level\fP" 10Configure the nesting level for storing flow files\&.  The default is 0\&.   -3    YYYY/YYYY-MM/YYYY-MM-DD/flow-file   -2    YYYY-MM/YYYY-MM-DD/flow-file   -1    YYYY-MM-DD/flow-file    0    flow-file    1    YYYY/flow-file    2    YYYY/YYYY-MM/flow-file    3    YYYY/YYYY-MM/YYYY-MM-DD/flow-file.IP "-p\fI pidfile\fP" 10Configure the process ID file\&.  Use - to disable pid file creation\&..IP "-R\fI rotate_program\fP" 10Execute \fIrotate_program\fP with the first argumentas the flow file name after rotating it\&..IP "-S\fI stat_interval\fP" 10When configured \fBflow-capture\fP will log a timestampedmessage every \fIstat_interval\fP minutesindicating counters such as the number of flows received, packets processed,and lost flows\&..IP "-t\fI tag_fname\fP" 10Load tags from \fBtag_name\fP.IP "-T\fI active_def\fP|\fIactive_def,active_def\&.\&.\&.\fP" 10Use \fIactive_def\fP as the active tag definition(s)\&..IP "-V\fI pdu_version\fP" 10Use \fIpdu_version\fP format output\&..PP.nf    1    NetFlow version 1 (No sequence numbers, AS, or mask)    5    NetFlow version 5    6    NetFlow version 6 (5+ Encapsulation size)    7    NetFlow version 7 (Catalyst switches)    8\&.1  NetFlow AS Aggregation    8\&.2  NetFlow Proto Port Aggregation    8\&.3  NetFlow Source Prefix Aggregation    8\&.4  NetFlow Destination Prefix Aggregation    8\&.5  NetFlow Prefix Aggregation    8\&.6  NetFlow Destination (Catalyst switches)    8\&.7  NetFlow Source Destination (Catalyst switches)    8\&.8  NetFlow Full Flow (Catalyst switches)    8\&.9  NetFlow ToS AS Aggregation    8\&.10 NetFlow ToS Proto Port Aggregation    8\&.11 NetFlow ToS Source Prefix Aggregation    8\&.12 NetFlow ToS Destination Prefix Aggregation    8\&.13 NetFlow ToS Prefix Aggregation    8\&.14 NetFlow ToS Prefix Port Aggregation    1005 Flow-Tools tagged version 5.fi.IP "-w\fI workdir\fP" 10Work in \fBworkdir\fP\&..IP "-z\fI z_level\fP" 10Configure compression level to \fI z_level\fP\&.  0 isdisabled (no compression), 9 is highest compression\&..SH "EXAMPLES".PPReceive flows from the exporter at 10\&.0\&.0\&.1 port 9800\&.  Maintain 5 Gigabytesof flow files in /flows/krc4\&.  Mask the source and destination IP addressescontained in the flow exports with 255\&.255\&.248\&.0\&..PP  \fBflow-capture -w /flows/krc4 -m 255\&.255\&.248\&.0 -E5G 0/10\&.0\&.0\&.1/9800\fP.PPReceive flows from any exporter on port 9800\&.  Do not perform any flowfile space management\&.  Store the exports in /flows/krc4\&.  Emit a statlog message every 5 minutes\&..PP  \fBflow-capture -w /flows/krc4 0/0/9800 -S5\fP.SH "BUGS".PPEmpty directories are not removed\&..SH "AUTHOR".PPMark Fullmer maf@splintered\&.net.SH "SEE ALSO".PP\fBflow-tools\fP(1)...\" created by instant / docbook-to-man, Wed 11 Dec 2002, 18:17

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -