On Wednesday 03 November 2010 20:38:41 Gary Gatten wrote:
> Notice total packets and ipv4 packets are both about 8.69M, but 34GB and
> 12GB respectively? Weird.
> 
> You're using sflow.  Would it be possible to connect to a SPAN port, tap,
> etc. and use libpcap as a test?  I'd be curious if ntop classifies the
> traffic the same as it does when using sflow...

Or even open some of the sflow packets in Wireshark and see what's in there.

alexd
_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop

Reply via email to