Interesting - do you have a lot of long living tcp connections?
What intervals do you use and what bandwith are you monitoring?
Thanks
- Peter
On 28.10.15 09:18, Maqbool Hashim wrote:
> Hi,
>
>
> I am running nfpcapd to convert live packet dump from a monitored switch port
> into nfdump format for later analysis. I find that nfpcapd rapidly consumes
> all available memory on the system and has to be killed or gets killed by the
> OOM killer.
>
>
> I am running NSEL-NEL1.6.13 version of nfdump.
>
>
> It is running on a Ubuntu system with a 3.16.0-34-generic kernel.
>
>
> I switched to using a different collector that captures the full traffic and
> outputs as netflow to nfcapd as a workaround. However thought you may be
> interested to know about this.
>
>
> Let me know if you require any further information.
>
>
>
> ------------------------------------------------------------------------------
>
>
>
> _______________________________________________
> Nfdump-discuss mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/nfdump-discuss
>
--
Be nice to your netflow data. Use NfSen and nfdump :)
------------------------------------------------------------------------------
_______________________________________________
Nfdump-discuss mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/nfdump-discuss