Hi,

I installed flow-tools following the instructions from
www.dynamicnetworks.us/netflow.

All funtions normally, the graphs are generated, at last its all OK.

2005/03/08 12:50:05 working on file
/var/netflow/ft-v05.2005-03-08.154501-0300...
2005/03/08 12:50:06 flowscan-1.020 CUFlow: Cflow::find took  1 wallclock
secs ( 0.20 usr +
0.00 sys =  0.20 CPU) for 31190 flow file bytes, flow hit ratio: 448/2050
2005/03/08 12:50:06 flowscan-1.020 CUFlow: report took  0 wallclock secs (
0.00 usr  0.00 sys
+  0.02 cusr  0.00 csys =  0.02 CPU)
sleep 30...
sleep 30...
sleep 30...
sleep 30...
sleep 30...
sleep 30...
sleep 30...
sleep 30...
sleep 30...
sleep 30...
2005/03/08 12:50:05 working on file
/var/netflow/ft-v05.2005-03-08.155001-0300...
2005/03/08 12:50:06 flowscan-1.020 CUFlow: Cflow::find took  0 wallclock
secs ( 0.20 usr +
0.00 sys =  0.20 CPU) for 31111 flow file bytes, flow hit ratio: 442/2045
2005/03/08 12:50:06 flowscan-1.020 CUFlow: report took  0 wallclock secs (
0.00 usr  0.00 sys
+  0.02 cusr  0.00 csys =  0.02 CPU)
sleep 30...
sleep 30...
sleep 30...
sleep 30...
sleep 30...
sleep 30...
sleep 30...
sleep 30...
sleep 30...
sleep 30...
2005/03/08 16:00:06 working on file
/var/netflow/ft-v05.2005-03-08.155500-0300...

Until here, all OK. But, after four or five hours of functioning, flowscan
does not works adequately. He stops the production of graphs and show the
error below:

[EMAIL PROTECTED] bin/flowscan
2005/03/08 13:16:48 working on file
/var/netflow/ft-v05.2005-03-08.125001-0300...
2005/03/08 13:16:48 flowscan-1.020 CUFlow: Cflow::find took  0 wallclock
secs ( 0.11 usr +  0.00 sys =  0.11 CPU) for 18019 flow file bytes, flow
hit ratio: 219/1203
2005/03/08 13:16:49 flowscan-1.020 CUFlow: report took  1 wallclock secs (
0.00 usr  0.01 sys +  0.00 cusr  0.01 csys =  0.02 CPU)
2005/03/08 13:16:49 working on file
/var/netflow/ft-v05.2005-03-08.125501-0300...
2005/03/08 13:16:49 flowscan-1.020 CUFlow: Cflow::find took  0 wallclock
secs ( 0.10 usr +  0.00 sys =  0.10 CPU) for 16759 flow file bytes, flow
hit ratio: 177/1107
2005/03/08 13:16:49 flowscan-1.020 CUFlow: report took  0 wallclock secs (
0.00 usr  0.01 sys +  0.01 cusr  0.00 csys =  0.02 CPU)
2005/03/08 13:16:49 working on file
/var/netflow/ft-v05.2005-03-08.130000-0300...
2005/03/08 13:16:49 flowscan-1.020 CUFlow: Cflow::find took  0 wallclock
secs ( 0.11 usr +  0.00 sys =  0.11 CPU) for 17175 flow file bytes, flow
hit ratio: 193/1146
2005/03/08 13:16:49 flowscan-1.020 CUFlow: report took  0 wallclock secs (
0.00 usr  0.00 sys +  0.00 cusr  0.03 csys =  0.03 CPU)
2005/03/08 13:16:49 working on file
/var/netflow/ft-v05.2005-03-08.130500-0300...
2005/03/08 13:16:49 flowscan-1.020 CUFlow: Cflow::find took  0 wallclock
secs ( 0.10 usr +  0.00 sys =  0.10 CPU) for 15816 flow file bytes, flow
hit ratio: 193/1045
2005/03/08 13:16:49 flowscan-1.020 CUFlow: report took  0 wallclock secs (
0.00 usr  0.00 sys +  0.01 cusr  0.00 csys =  0.01 CPU)
2005/03/08 13:16:49 working on file
/var/netflow/ft-v05.2005-03-08.131001-0300...
2005/03/08 13:16:49 flowscan-1.020 CUFlow: Cflow::find took  0 wallclock
secs ( 0.12 usr +  0.00 sys =  0.12 CPU) for 17016 flow file bytes, flow
hit ratio: 235/1150
ERROR updating /var/netflow/rrds/tos_normal.rrd: could not lock RRD
ERROR updating /var/netflow/rrds/total.rrd: illegal attempt to update
using time 1110297900 when last update time is 1110298201 (minimum one
second step)
ERROR updating /var/netflow/rrds/routerrr2/total.rrd: illegal attempt to
update using time 1110297900 when last update time is 1110298201 (minimum
one second step)
ERROR updating /var/netflow/rrds/protocol_multicast.rrd: illegal attempt
to update using time 1110297900 when last update time is 1110298201
(minimum one second step)
ERROR updating /var/netflow/rrds/routerrr2/protocol_multicast.rrd: illegal
attempt to update using time 1110297900 when last update time is
1110298201 (minimum one second step)
ERROR updating /var/netflow/rrds/tos_normal.rrd: could not lock RRD
ERROR updating /var/netflow/rrds/routerrr2/tos_normal.rrd: could not lock
RRD
2005/03/08 13:16:50 flowscan-1.020 CUFlow: report took  1 wallclock secs (
0.00 usr  0.00 sys +  0.02 cusr  0.01 csys =  0.03 CPU)
sleep 30...
ERROR updating /var/netflow/rrds/routerrr2/tos_normal.rrd: could not lock
RRD
ERROR updating /var/netflow/rrds/tos_other.rrd: could not lock RRD
ERROR updating /var/netflow/rrds/routerrr2/tos_other.rrd: could not lock
RRD
ERROR updating /var/netflow/rrds/routerrr2/tos_other.rrd: could not lock
RRD
ERROR updating /var/netflow/rrds/protocol_tcp.rrd: could not lock RRD
ERROR updating /var/netflow/rrds/protocol_tcp.rrd: could not lock RRD
ERROR updating /var/netflow/rrds/routerrr2/protocol_tcp.rrd: could not
lock RRD
ERROR updating /var/netflow/rrds/routerrr2/protocol_tcp.rrd: could not
lock RRD
ERROR updating /var/netflow/rrds/protocol_esp.rrd: could not lock RRD
ERROR updating /var/netflow/rrds/routerrr2/protocol_esp.rrd: could not
lock RRD
ERROR updating /var/netflow/rrds/routerrr2/protocol_esp.rrd: could not
lock RRD
ERROR updating /var/netflow/rrds/protocol_skip.rrd: could not lock RRD
ERROR updating /var/netflow/rrds/protocol_skip.rrd: could not lock RRD
ERROR updating /var/netflow/rrds/routerrr2/protocol_skip.rrd: could not
lock RRD
ERROR updating /var/netflow/rrds/routerrr2/protocol_skip.rrd: could not
lock RRD
ERROR updating /var/netflow/rrds/protocol_ah.rrd: could not lock RRD
ERROR updating /var/netflow/rrds/routerrr2/protocol_ah.rrd: could not lock
RRD
ERROR updating /var/netflow/rrds/routerrr2/protocol_ah.rrd: could not lock
RRD
ERROR updating /var/netflow/rrds/protocol_udp.rrd: could not lock RRD
ERROR updating /var/netflow/rrds/protocol_udp.rrd: could not lock RRD
ERROR updating /var/netflow/rrds/routerrr2/protocol_udp.rrd: could not
lock RRD


My flow files:

-rw-r--r--    1 root     root        31734 Mar  8 14:40
ft-v05.2005-03-08.143501-0300
-rw-r--r--    1 root     root        32299 Mar  8 14:45
ft-v05.2005-03-08.144001-0300
-rw-r--r--    1 root     root        29422 Mar  8 14:50
ft-v05.2005-03-08.144501-0300
-rw-r--r--    1 root     root        31691 Mar  8 14:55
ft-v05.2005-03-08.145001-0300
-rw-r--r--    1 root     root        34400 Mar  8 15:00
ft-v05.2005-03-08.145500-0300
-rw-r--r--    1 root     root        31985 Mar  8 15:05
ft-v05.2005-03-08.150001-0300
-rw-r--r--    1 root     root        27578 Mar  8 15:10
ft-v05.2005-03-08.150501-0300
-rw-r--r--    1 root     root        27190 Mar  8 15:15
ft-v05.2005-03-08.151000-0300
-rw-r--r--    1 root     root        27412 Mar  8 15:20
ft-v05.2005-03-08.151501-0300
-rw-r--r--    1 root     root        29669 Mar  8 15:25
ft-v05.2005-03-08.152000-0300
-rw-r--r--    1 root     root        27908 Mar  8 15:30
ft-v05.2005-03-08.152501-0300
-rw-r--r--    1 root     root           84 Mar  8 15:30
tmp-v05.2005-03-08.153001-0300


These archives are located in /var/netflow/ft. Some times, the temporary
archive  tmp-v05.2005-03-08... is created in /var/netflow, pointing for the
same file in /var/netflow/ft.  These archives are discarded after to be
used, but some times they are not descarded.I
believe that the flowscan it is confused when this it happens, because it
is in this point that the error it occurs.

Somebody know how to fix this problem?

Best regards,

Fabr�cio.

**********************************************************************************

As informa��es contidas nesta mensagem e no(s) arquivo(s) anexo(s) s�o
endere�adas exclusivamente �(s) pessoa(s) e/ou institui��o(�es) acima
indicada(s), podendo conter dados confidenciais, os quais n�o podem, sob
qualquer forma ou pretexto, ser utilizados, divulgados, alterados,
impressos ou copiados, total ou parcialmente, por pessoas n�o autorizadas.
Caso n�o seja o destinat�rio, favor providenciar sua exclus�o e notificar
o remetente imediatamente.  O uso impr�prio ser� tratado conforme as
normas da empresa e da legisla��o em vigor.
Esta mensagem expressa o posicionamento pessoal do subscritor e n�o
reflete necessariamente a opini�o da Serasa.
**********************************************************************************


_______________________________________________
Flow-tools mailing list
[EMAIL PROTECTED]
http://mailman.splintered.net/mailman/listinfo/flow-tools

Reply via email to