Re: [Ntop] asa netflow vs switch flexible netflow

2017-03-07 Thread Luca Deri
Hi Matt ASA (like PaloAlto and many others) are firewall devices that emit flows when the flow starts and when the flow ends, this adding a verdict (e.g. pass or drop according to firewall rules). ASA is a family of devices and not all area alike, so configuration and ASA model can make quite so

[Ntop] asa netflow vs switch flexible netflow

2017-03-07 Thread Matt Kettler
I asked part of this question previously, but it was buried in another thread where I was trying to fix problems. I'm currently exporting netflows from an asa and using nprobe on an evaluation basis to zmq that to ntopng. However, I'm reading the ASA's implementation of netflow isn't exactly "f

Re: [Ntop] Historical IP and/or protocol reports

2017-03-07 Thread Warren Daly (OPUS)
Hi Simone, I am using ntopng Pro [Small Business Edition] v.2.4.170215 and I get it from http://www.nmon.net/apt-stable/14.04 I'm running Ubuntu 14.04 LTS. Thanks, Warren On 08/03/17 05:28, Simone Mainardi wrote: Warren, are you using the latest dev version? On Tue, Mar 7, 2017 at 9:32

Re: [Ntop] ntopng+nprobe+cisco asa netflow - now all times = asa reboot time.

2017-03-07 Thread Matt Kettler
Well, I tried a full teardown and upgraded again... this time, I have hosts, and valid timestamps. Not sure why my upgrade didn't work correctly, unless the fix hadn't propagated to the nightly builds yet.. From: ntop-boun...@listgateway.unipi.it on behalf

Re: [Ntop] ntopng+nprobe+cisco asa netflow - now all times = asa reboot time.

2017-03-07 Thread Simone Mainardi
Matt, On Tue, Mar 7, 2017 at 11:29 PM, Matt Kettler wrote: > Using the latest dev build isn’t a viable option until the zmq hosts issue > is fixed. > > > > I tried updating before I went back to stable.. it is most definitely NOT > fixed. > Our latest tests confirm the issue is fixed. If you th

Re: [Ntop] ntopng+nprobe+cisco asa netflow - now all times = asa reboot time.

2017-03-07 Thread Matt Kettler
Using the latest dev build isn’t a viable option until the zmq hosts issue is fixed. I tried updating before I went back to stable.. it is most definitely NOT fixed. From: ntop-boun...@listgateway.unipi.it [mailto:ntop-boun...@listgateway.unipi.it] On Behalf Of Simone Mainardi Sent: Tuesday, Ma

Re: [Ntop] Historical IP and/or protocol reports

2017-03-07 Thread Simone Mainardi
Warren, are you using the latest dev version? On Tue, Mar 7, 2017 at 9:32 AM, Warren Daly (OPUS) wrote: > Hi, > > there is no log entry in /var/log/ntopng/ntopng.log > > I have 2 issues: > > > ISSUE A: > > /lua/if_stats.lua?id=36&page=historical > The chart works. > Talkers = No Results Found >

Re: [Ntop] ntopng+nprobe+cisco asa netflow - now all times = asa reboot time.

2017-03-07 Thread Simone Mainardi
Matt, On Mon, Mar 6, 2017 at 4:48 AM, Matt Kettler wrote: > ​I take that back, the stable version demonstrates a different problem: > > > It thinks that the current flows, as well as the hosts, are all quite old > (over 1 month). In fact, they're all first and last seen on the exact same > date

Re: [Ntop] Historical IP and/or protocol reports

2017-03-07 Thread Warren Daly (OPUS)
Hi, there is no log entry in /var/log/ntopng/ntopng.log I have 2 issues: ISSUE A: /lua/if_stats.lua?id=36&page=historical The chart works. Talkers = No Results Found Protocols = No Results Found No time range will display the 'IPv4 Flows' tab unless its 1 week or more. Clicking on "IPv4 Flo