You configure traffic sampling results to a file in the /var/tmp directory. To collect the sampled packets in a file, include the file statement at the [edit forwarding-options sampling output] hierarchy level:
- [edit forwarding-options sampling output]
-
file {
- disable;
-
filename filename;
-
files number;
- size bytes;
- (stamp | no-stamp);
- (world-readable | no-world-readable);
- }
To configure the period of time before an active flow is exported, include the flow-active-timeout statement at the [edit forwarding-options sampling output] hierarchy level:
- [edit forwarding-options sampling output]
- flow-active-timeout seconds;
To configure the period of time before a flow is considered inactive, include the flow-inactive-timeout statement at the [edit forwarding-options sampling output] hierarchy level:
- [edit forwarding-options sampling output]
- flow-inactive-timeout seconds;
To configure the interface, include the interface statement at the [edit forwarding-options sampling output] hierarchy level:
- [edit forwarding-options sampling output]
- interface [ interface-names ] {
- engine-id number;
- engine-type number;
- source-address address;
- }
To configure the interval before exporting an active flow, include the flow-active-timeout statement. To configure the interval before a flow is considered inactive, include the flow-inactive-timeout statement. To configure the interface that sends out monitored information, include the interface statement.
![]() |
Note: This feature is not supported with the version 9 template format. You must send traffic flows collected using version 9 to a server. For more information see Configuring Active Flow Monitoring Using Version 9. |
Traffic sampling output is saved to an ASCII text file. The following is an example of the traffic sampling output that is saved to a file in the /var/tmp directory. Each line in the output file contains information for one sampled packet. You can optionally display a timestamp for each line.
The column headers are repeated after each group of 1000 packets.
# Apr 7 15:48:50
Time Dest Src Dest Src Proto TOS Pkt Intf IP TCP
addr addr port port len num frag flags
Apr 7 15:48:54 192.168.9.194 192.168.9.195 0 0 1 0x0 84 8 0x0 0x0
Apr 7 15:48:55 192.168.9.194 192.168.9.195 0 0 1 0x0 84 8 0x0 0x0
Apr 7 15:48:56 192.168.9.194 192.168.9.195 0 0 1 0x0 84 8 0x0 0x0
Apr 7 15:48:57 192.168.9.194 192.168.9.195 0 0 1 0x0 84 8 0x0 0x0
Apr 7 15:48:58 192.168.9.194 192.168.9.195 0 0 1 0x0 84 8 0x0 0x0
The output contains the following fields:
To set the timestamp option for the file my-sample, enter the following:
- [edit forwarding-options sampling output file]
- user@host# set filename my-sample files 5
size 2m world-readable stamp;
Whenever you toggle the timestamp option, a new header is included in the file. If you set the stamp option, the Time field is displayed.
# Apr 7 15:48:50 # Time Dest Src Dest Src Proto TOS Pkt Intf IP TCP # addr addr port port len num frag flags # Feb 1 20:31:21 # Dest Src Dest Src Proto TOS Pkt Intf IP TCP # addr addr port port len num frag flags