Hi to all;

I realized now why the two values was different. It was my channel filters in 
my new profile which is wrong. Since a Send and Receive packet are considered 2 
flows, i should set "src ip 10.157.xxx.yyy or dst ip 10.157.xxx.yyy" (for a 
send and receive packet of 10.157.xxx.yyy). My nfdump query now from live to my 
new profile now match.


Live
Top 10 IP Addr ordered by flows:
Date first seen          Duration Proto           IP Addr    Flows(%)     
Packets(%)       Bytes(%)         pps      bps   bpp
2010-06-29 22:20:00.218   297.877 any       10.157.xxx.yyy      391(75.6)     
7820(75.6)   612500(67.3)       26    16449    78
2010-06-29 22:20:00.218   297.877 any       204.92.xxx.yyy       96(18.6)     
1920(18.6)   118400(13.0)        6     3179    61

NewProfile

Top 10 IP Addr ordered by flows:
Date first seen          Duration Proto           IP Addr    Flows(%)     
Packets(%)       Bytes(%)         pps      bps   bpp
2010-06-29 22:20:00.218   297.877 any       10.157.xxx.yyy      391(100.0)     
7820(100.0)   612500(100.0)       26    16449    78
2010-06-29 22:20:00.218   297.877 any       204.92.xxx.yyy      96(24.6)     
1920(24.6)   118400(19.3)        6     3179    61



--Mike


--- On Tue, 6/29/10, Michael P. Carel <[email protected]> wrote:

> From: Michael P. Carel <[email protected]>
> Subject: Re: [Nfsen-discuss] Profile Channel List Filter
> To: "[email protected]" 
> <[email protected]>
> Date: Tuesday, June 29, 2010, 5:16 PM
> Thanks for the reply, but i'm
> confused in the nfdump output after applying the source ip
> filter. The values are different compared to the live
> profile, even if the query was in the same time range and
> channel source.
> 
> Example:
> 
> For Live Profile, channelsource peer1, time: tstart 
> 2010-06-29-15-15  tend 2010-06-29-16-15  
> 
> Top 10 IP Addr ordered by flows:
> Date first seen          Duration
> Proto           IP
> Addr    Flows(%) 
>    Packets(%)   
>    Bytes(%)     
>    pps     
> bps   bpp
> 2010-06-29 15:15:00.400  3896.836 any   
>    10.157.xxx.yyy 
>    8421(100.0)   168420(100.0)   21.7
> M(100.0)       43   
> 44552   128
> 2010-06-29 15:15:00.400  3896.836 any   
>    204.92.xxx.yyy 
>    3047(36.2)    60940(36.2) 
>   6.8 M(31.2)       15 
>   13900   111
> 2010-06-29 15:15:00.400  3896.836 any   
>     69.63.xxx.yyy  1263(15.0)   
> 25260(15.0)    3.7 M(16.8)     
>   6     7498   144
> 
> 
> For New Profile, channelsource peer1, Filter source ip
> 10.157.xxx.yyy time: tstart  2010-06-29-15-15 
> tend 2010-06-29-16-15  
> 
> Top 10 IP Addr ordered by flows:
> Date first seen          Duration
> Proto           IP
> Addr    Flows(%) 
>    Packets(%)   
>    Bytes(%)     
>    pps     
> bps   bpp
> 2010-06-29 15:15:00.400  3896.836 any   
>    10.157.xxx.yyy 
> 6639(100.0)   132780(100.0)    9.8
> M(100.0)       34   
> 20078    73
> 2010-06-29 15:15:00.400  3896.836 any   
>    204.92.xxx.yyy  2401(36.2) 
>   48020(36.2)    3.6 M(36.4)   
>    12     7310 
>   74
> 2010-06-29 15:15:00.400  3896.836 any   
>     69.63.xxx.yyy  1049(15.8)   
> 20980(15.8)    1.7 M(17.8)     
>   5     3577    83
> 
> What I assume is that they should have the same values.
> 
> 
> --Mike
> 
> --- On Tue, 6/29/10, Vandivier, Bryan <[email protected]>
> wrote:
> 
> > From: Vandivier, Bryan <[email protected]>
> > Subject: Re: [Nfsen-discuss] Profile Channel List
> Filter
> > To: "Michael P. Carel" <[email protected]>
> > Cc: "[email protected]"
> <[email protected]>
> > Date: Tuesday, June 29, 2010, 11:17 AM
> > You only need to specify the source
> > IP.  The additional syntax is unnecessary.
> > 
> > 
> > 
> > 
> > 
> > 
> > On Jun 28, 2010, at 10:06 PM, "Michael P. Carel"
> <[email protected]>
> > wrote:
> > 
> > > Hi to all;
> > > 
> > > I have questions in the traffic generated when
> setting
> > channel filter.
> > > 
> > > I used to create Profile and set channel filters
> as
> > "src ip 10.157.xxx.yyy and dst ip 0.0.0.0". When
> creating
> > this type of filter, the graph data for traffic ,
> packet and
> > flows will just only be for the source ip
> 10.157.xxx.yyy
> > with a destination ip 0.0.0.0(any)? 
> > > 
> > > I need to know the data only for ip
> 10.157.xxx.yyy
> > that's why i've created this filter. Please tell me if
> i'm
> > in the right track.
> > > 
> > > 
> > > Thanks in advance.
> > > 
> > > 
> > > --Mike
> > > 
> > > 
> > > 
> > > 
> > >
> >
> ------------------------------------------------------------------------------
> > > This SF.net email is sponsored by Sprint
> > > What will you do first with EVO, the first 4G
> phone?
> > > Visit sprint.com/first -- http://p.sf.net/sfu/sprint-com-first
> > > _______________________________________________
> > > Nfsen-discuss mailing list
> > > [email protected]
> > > https://lists.sourceforge.net/lists/listinfo/nfsen-discuss
> > 
> 
> 
>       
> 
> ------------------------------------------------------------------------------
> This SF.net email is sponsored by Sprint
> What will you do first with EVO, the first 4G phone?
> Visit sprint.com/first -- http://p.sf.net/sfu/sprint-com-first
> _______________________________________________
> Nfsen-discuss mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/nfsen-discuss
> 


      

------------------------------------------------------------------------------
This SF.net email is sponsored by Sprint
What will you do first with EVO, the first 4G phone?
Visit sprint.com/first -- http://p.sf.net/sfu/sprint-com-first
_______________________________________________
Nfsen-discuss mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/nfsen-discuss

Reply via email to