Welcome, Guest. Please login or register.

Recent Posts

Pages: 1 2 [3] 4 5 ... 10
21
Discovery / Issue Configuring and Using netflow
« Last post by knottyau75 on August 27, 2018, 07:55:30 AM »
Hi All,  Hoping someone can help me.

I've used Configured a New NEdi install using Ubuntu 17.10 and the Script that Remo has made avialable on the Website.  Its all Running fine except for Flowi.pl.

The Collector is running and the Files are being stored in fine in /var/cache/ndump.

If I manually run nfdump -r /var/cache/nfdump/nfcapd.201808271534  I get an output.

But,  If I run /var/nedi/flowi.pl -v, it returns the Following

Code: [Select]
nedi@auqldrv00nwm1ai:/var/cache/nfdump$ sudo /var/nedi/flowi.pl -v
RRD :nfdump -M /var/cache/nfdump/nfcapd.201808271526:nfcapd.201808271529:nfcapd.201808271534:nfcapd.201808271539:nfcapd.201808271544:nfcapd.current.1009 -r nfcapd.201808271540 using packets
stat() error '/var/cache/nfdump/nfcapd.201808271526/nfcapd.201808271540': Not a directory
stat() error '/var/cache/nfdump/nfcapd.201808271526/nfcapd.201808271540': Not a directory
TRRD:/var/nedi/rrd/flow.rrd update OK
ALRT:0 mails and 0 SMS sent

and, of course, the RRD file has nothing in it.

my nedi.conf file has the Following in it

Code: [Select]
# Path to nfdump data files
nfdpath /var/cache/nfdump

# Top 10 netflow ports
# flow.rrd needs to be recreated after changes (can be achieved by deleting Flow RRD in System-Files)
nfport 22 ssh
nfport 23 telnet
nfport 25 smtp
nfport 53 dns
nfport 123 ntp
nfport 80 http
nfport 443 https
nfport 445 cifs
nfport 3260 iscsi
nfport 3389 rdp

And the Directory looks like

Code: [Select]
nedi@auqldrv00nwm1ai:/var/cache/nfdump$ ls -l
total 204392
-rw-r--r-- 1 root root 16390980 Aug 27 15:28 nfcapd.201808271526
-rw-r--r-- 1 root root 43134252 Aug 27 15:34 nfcapd.201808271529
-rw-r--r-- 1 root root 42600480 Aug 27 15:39 nfcapd.201808271534
-rw-r--r-- 1 root root 40525656 Aug 27 15:44 nfcapd.201808271539
-rw-r--r-- 1 root root 39363144 Aug 27 15:49 nfcapd.201808271544
-rw-r--r-- 1 root root 27263152 Aug 27 15:52 nfcapd.current.1009


I also cannot query the Dump files from the GUI (not sure if that is related or not)

Any Idea's?



Thanks in Advance

Knotty

22
Definition Files / Re: Enterasys S4 Chassis
« Last post by SchmuFoo on August 24, 2018, 11:27:19 AM »
CPU seems to be:
1.3.6.1.4.1.5624.1.2.49.1.1.1.1.4.10011002.1 = INTEGER: 146
1.3.6.1.4.1.5624.1.2.49.1.1.1.1.4.10011003.1 = INTEGER: 86

Memory:
1.3.6.1.4.1.5624.1.2.49.1.3.1.1.5.10011002.2.1 = Gauge32: 50741
1.3.6.1.4.1.5624.1.2.49.1.3.1.1.5.10011002.3.1 = Gauge32: 27864
1.3.6.1.4.1.5624.1.2.49.1.3.1.1.5.10011002.3.2 = Gauge32: 63232
1.3.6.1.4.1.5624.1.2.49.1.3.1.1.5.10011002.3.3 = Gauge32: 823664
1.3.6.1.4.1.5624.1.2.49.1.3.1.1.5.10011003.2.1 = Gauge32: 59815
1.3.6.1.4.1.5624.1.2.49.1.3.1.1.5.10011003.3.1 = Gauge32: 27864
1.3.6.1.4.1.5624.1.2.49.1.3.1.1.5.10011003.3.2 = Gauge32: 63228
1.3.6.1.4.1.5624.1.2.49.1.3.1.1.5.10011003.3.3 = Gauge32: 822608

Which matches the output of show system utilization:

Storage Utilization:

Slot: 2

Type        Description               Size (Kb)      Available (Kb)
-------------------------------------------------------------------
 RAM        RAM device 1                1048576               50744
 FLASH      Images                        64040               27864
 FLASH      Nonvolatile Data Storage      64584               63232
 FLASH      Miscellaneous Storage        824128              823664


Slot: 3

Type        Description               Size (Kb)      Available (Kb)
-------------------------------------------------------------------
 RAM        RAM device 1                1048576               59815
 FLASH      Images                        64040               27864
 FLASH      Nonvolatile Data Storage      64584               63228
 FLASH      Miscellaneous Storage        824128              822608
23
Discovery / Re: Write Nodes: "Loop .. belongs to this device .."
« Last post by SchmuFoo on August 24, 2018, 09:31:52 AM »
Nope, the addresses are the Burned-in-MACs. On this single device 449 loop messages  ::)
24
Definition Files / Re: Enterasys S4 Chassis
« Last post by SchmuFoo on August 24, 2018, 08:54:03 AM »
Found OID for:

Serial#: 1.3.6.1.2.1.47.1.1.1.1.11.10001001
Bootimage: 1.3.6.1.2.1.47.1.1.1.1.10.10011002
25
News / DHCP based OS fingerprinting
« Last post by rickli on August 21, 2018, 12:15:48 PM »
Thanks to the ingenious minds over at www.dumplab.ch, you can have DHCP based OS fingerprinting for NeDi nodes. And best of all, it's free!

https://github.com/dumplab/dhcpfingerprint
26
Discovery / Re: MACFLOOD Treshold Settings
« Last post by rickli on August 21, 2018, 11:42:06 AM »
Look for binoculars in the input form. It's the 3rd number field...
27
Discovery / Re: Write Nodes: "Loop .. belongs to this device .."
« Last post by rickli on August 21, 2018, 11:40:12 AM »
Is this an interlink on a stack? If so, try adding the MAC to ignoredmacs in nedi.conf...
28
Definition Files / Re: Def for Cisco C9300-24P
« Last post by rickli on August 21, 2018, 11:32:02 AM »
Try this for Poe:
IFpowr   1.3.6.1.4.1.9.9.402.1.2.1.9   N
29
Definition Files / Re: Dell Def files request
« Last post by harry on August 19, 2018, 03:18:43 PM »
Any one....Help please.....
30
Definition Files / Re: Enterasys S8-Chassis Bonded
« Last post by SchmuFoo on August 17, 2018, 02:19:22 PM »
Found OID for VLAN Name: 1.3.6.1.2.1.17.7.1.4.3.1.1
Pages: 1 2 [3] 4 5 ... 10