Debugging cflowd Flow Aggregation
To collect the cflowd flows in a log file before they are exported, include the
local-dumpstatement at the[edit forwarding-options sampling output cflowdhostname]hierarchy level:local-dump;By default, the flows are collected in
/var/log/sampled; to change the filename, include thefilenamestatement at the[edit forwarding-options sampling traceoptions]hierarchy level. For more information about changing the filename, see Configuring Traffic Sampling Output.
NOTE: Because the
local-dumpstatement adds extra overhead, you should use it only while debugging cflowd problems, not during normal operation.
The following is an example of the flow information. The AS number exported is the origin AS number. All flows that belong under a cflowd header are dumped, followed by the header itself:
Jun 27 18:35:43 v5 flow entryJun 27 18:35:43 Src addr: 192.53.127.1Jun 27 18:35:43 Dst addr: 192.6.255.15Jun 27 18:35:43 Nhop addr: 192.6.255.240Jun 27 18:35:43 Input interface: 5Jun 27 18:35:43 Output interface: 3Jun 27 18:35:43 Pkts in flow: 15Jun 27 18:35:43 Bytes in flow: 600Jun 27 18:35:43 Start time of flow: 7230Jun 27 18:35:43 End time of flow: 7271Jun 27 18:35:43 Src port: 26629Jun 27 18:35:43 Dst port: 179Jun 27 18:35:43 TCP flags: 0x10Jun 27 18:35:43 IP proto num: 6Jun 27 18:35:43 TOS: 0xc0Jun 27 18:35:43 Src AS: 7018Jun 27 18:35:43 Dst AS: 11111Jun 27 18:35:43 Src netmask len: 16Jun 27 18:35:43 Dst netmask len: 0[... 41 more version 5
flowentries; then the following header:]Jun 27 18:35:43 cflowd header:Jun 27 18:35:43 Num-records: 42Jun 27 18:35:43 Version: 5Jun 27 18:35:43 Flow seq num: 118Jun 27 18:35:43 Engine id: 0Jun 27 18:35:43 Engine type: 3