-
Notifications
You must be signed in to change notification settings - Fork 262
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
IPFIX & nano seconds timestamps #732
Comments
Hi Jurgen ( @jukrut ), Just to confirm that nano seconds counters are currently not supported. I guess this is not a biggie in terms of development and i may have something working maybe next week. Just please confirm me that this is a priority for you to have it working. Paolo |
I can't easily change the tool that exports the ipfix, I just did a ipfix-generator that mimics the behaviour of the dataplane to easliy test the behaviour. So yes I would be very happy If you could add support for nanoseconds. And thank you very much for the great software and always so quick and helpful responses. |
I managed to get around this by changing the tool that sends the ipfix packets. If you don't plan to implement it, |
Hi Jurgen ( @jukrut ), Thanks for this note & good to know you have a workaround. I could add a warning meanwhile although i'd still be planning to look into this and implement it. One thing that did catch my attention is that flowStartNanoseconds and flowEndNanoseconds are 8 bytes, it seems enough space only for an offset to some other base timestamp (and not an absolute value); like, flowStartMicroseconds and flowEndMicroseconds are 16 bytes long in the implementations that i did come across. Paolo |
Description
I have Problems to get timestamp_end, timestamp_start display the correct value.
I found a issue mailthread (https://www.mail-archive.com/pmacct-discussion@pmacct.net/msg03195.html) but that did not help so I open a ticket to ask for your help.
I run nfacctd like this:
and with pmacctd like this:
nfacct displays it perfectly fine.
but with my generator it always has 0 for timestamp_end and the timestamp_start has the time of end.
e.g.
and wireshark decodes it like this:
the full ipfix messages are uploaded below:
ipfix.pcapng.zip
the main difference that I see is that I use nanoseconds and pmacct microseconds..
Do you see any Problems with the IPFix Messages?
Version
I would say all.. but I just tested with 1.7.7, 1.7.8 and master
The text was updated successfully, but these errors were encountered: