Der Vortrag wurde auf dem openITCOCKPIT Monitoring Summit 2024 gehalten. Es wird eine Einführung zu Netflow gegeben und erklärt wie OpenNMS mit flows umgeht, wie Installationen in verschiedenen Szenarien aussehen.
Destin a tion IP Source Port Destin a tion Port Interf a ce Protocol Bytes 192.168.1.23 104.125.70.17 38274 443 1 6 400 cdn.pl a yst a tion.com your.box. a t.your.corp
a Listener Source IP Destin a tion IP Source Port Destin a tion Port Interf a ce Protocol Bytes 192.168.1.23 104.125.70.17 38274 443 1 6 400 https eth0 tcp cdn.pl a yst a tion.com your.box. a t.your.corp C a tegories Loc a tion Invent a r ID’s
a Listener Source IP Destin a tion IP Source Port Destin a tion Port Interf a ce Protocol Bytes 192.168.1.23 104.125.70.17 38274 443 1 6 400 https eth0 tcp cdn.pl a yst a tion.com your.box. a t.your.corp C a tegories Loc a tion Invent a r ID’s
Cisco Cisco (RFC 3954) Open (RFC 7012) Open (RFC 3176) Flow b a sed or s a mpled Flow b a sed or s a mpled Flow b a sed or s a mpled S a mpled Ingress Only Ingress/Egress Ingress/Egress Ingress/Egress IPv4 IPv4/IPv6/VLAN/MPLS IPv4/IPv6/VLAN/MPLS IPv4/IPv6/VLAN/MPLS St a tic Extensible Extensible Extensible
Destin a tion Port Interf a ce Protocol Bytes Routing Source AS Source a utonomous system number. Routing Destin a tion AS Destin a tion a utonomous system number. Routing Next-hop Address IP a ddress of the next hop. IP Source M a sk M a sk for the IP source a ddress. IP Destin a tion M a sk M a sk for the IP destin a tion a ddress. Tr a nsport TCP Fl a gs V a lue in the TCP fl a g fi eld.
IP Source Port Destin a tion Port Interf a ce Protocol Bytes 192.168.1.23 104.125.70.17 38274 443 1 6 400 cdn.pl a yst a tion.com your.box. a t.your.corp
Destin a tion Port Interf a ce Protocol Bytes 192.168.1.23 104.125.70.17 38274 443 1 6 400 OpenNMS Invent a r https eth0 tcp C a tegories Loc a tion Invent a r ID’s
Port Destin a tion Port Interf a ce Protocol Bytes 192.168.1.23 104.125.70.17 38274 443 1 6 400 OpenNMS Invent a r https eth0 tcp C a tegories Loc a tion Invent a r ID’s
sic.html • https://blog.s f low.com/2022/02/udp-vs-tcp-for-re a l-time-stre a ming.html • https://opennms.discourse.group/t/how-to-use-pm a cct- a s- a -net f low-9-probe-on-ubuntu-linux- a nd-m a c-os-big-sur/1160 • https://opennms.discourse.group/t/running-in-docker- a nd-receiving- f lows-tr a ps-or-syslog-mess a ges-over-udp/1103 • https://www.v a ronis.com/blog/ f low-monitoring • https://ch a t.opennms.com/opennms/ch a nnels/opennms-discussion • https://github.com/OpenNMS/el a sticse a rch-drift-plugin