-
Notifications
You must be signed in to change notification settings - Fork 262
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Aggregation primitives definition based on netflow template #602
Comments
Hi @ixodis , This is not possible but, in some form of it to be studied, it could definitely be a good idea to implement. I am going to mark this as Paolo |
Hi @paololucente, I have a similar case where two OS versions of Cisco WLC have two definition of the same field : I tried a workaround by static mapping tag & flowset id & aggregate-primitive file : Conf file : But it seems I can't configure aggregate_primitives file by tag : Would you please confirm I'm on the wrong way (or not), is there a planning to implement "Aggregation primitives definition based on netflow template" ? Best regards, Laurent |
Hi Laurent ( @laurentduru ), I got your use-case here and, unfortunately, i can confirm that currently the only way you can resolve this - as you were saying - is to run separate nfacctd instances. Paolo |
Hi Paolo (@paololucente); Many thanks for your answer, we gave a try to a len=vlen definition for this primitive, it's seems to do the job. Regards, |
Hi Laurent ( @laurentduru ), Thank you VERY MUCH for reporting back about this finding. You are right As a side node, this issue can't be closed since this still won't work for the OP since (s)he is using Paolo |
Hi Paolo!
I have problems with flowID (#148) field. Cisco ASA allocates 4 bytes for it and Palo Alto – 8 bytes, so I can’t use one instance of nfacctd to process netflow from Cisco and Palo Alto simultaneously. I have to run two nfacctds with different primitives lists:
This one for Cisco:
And this one for PA:
Is it possible to define aggregation primitives automatically based on information from template file that already contains all the information about fields?
The text was updated successfully, but these errors were encountered: