Comments (2)
Isn't it easier and more "UNIX" to just use IPFIXcol[v2] for the conversion? Otherwise the inconsistencies will appear inevitably.
from nemea-modules.
Well... if flow_meter
was primarily an IPFIX exporter, it would be better...
I feel that current status (and usage of flow_meter
) is to run it as a standalone source of UniRec data for experiments and development of NEMEA modules.
It is probably the most frequent use-case for it.
In such case, we need to operate directly with UniRec templates in the flow_meter
which are currently hard-coded.
@jaroslavh wishes to do his bachelor thesis about flow_meter
and its deployment on OpenWrt. We should brainstorm for a while. (In fact, we have already started.)
What we need from flow_meter
and what we can change before the thesis submission deadline?
My opinion, flow_meter
could be reworked so the internal representation and the main format would be in IPFIX and then we can use translation into UniRec very similarly to IPFIXcol2 UniRec plugin...
Or naturally, we could use IPFIXcol2 to do the translation.
Disadvantage of IPFIXcol2 is quite clear for the "manual" experiments: instead of just starting flow_meter
with UniRec output that can be "subscribed" by any NEMEA module, we would start the collector, which must be configured - this solution is not so easy-to-use.
This issue comes from the work of @sustefil, who is working on new blacklistfilters, because he tested the code with the output of flow_meter
and he discovered incompatible templates during the deployment to our CESNET collector.
The point is that if anyone (from us) adds a new plugin into flow_meter
we should try to make it compatible with existing modules (i.e., with the currently used templates on the collector) no matter if the collector is configurable (its configuration probably won't be changed in the future because of the already running modules).
from nemea-modules.
Related Issues (20)
- Create a simple README.md for json_dump HOT 2
- logger bug: `-o` parameter doesn't work
- Module `sni_dataset_saver` is missing a `<cstdint>` include HOT 1
- unirecfilter: Unable to filter fields containing number
- Feature request: Add DNS A record for dns plugin (flow_meter)
- Question: DIR_BIT_FIELD of interface network HOT 2
- 'uint64 BYTES' in openWRT always has zero value HOT 2
- Improvement of README (merger)
- Reporter modules crash on db connection error HOT 1
- Unirecfilter startup race HOT 5
- Unirecfilter infinite loop
- ipblacklist does not list dst IP address in idea message HOT 1
- anonymizer: unchecked rv of fgets! HOT 4
- vportscan aggregation logger does not work HOT 4
- json_dump.py flushing HOT 2
- vportscan AggrWin is fixed HOT 2
- Warning shebang in python scripts/modules HOT 10
- Unirecfilter: Support for "IN" operator for IP prefix HOT 2
- Build fails on openSUSE 15 HOT 6
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from nemea-modules.