Open bruceg opened 4 years ago
There is flowEndReason
option you can examine for single packet flows. If its value is 1
it's mean flow is terminated by FIN or RST, if it's 3
it's terminated by inactive timeout, 2
inactive timeout. Also, you may look at tcp_flags
to see if there is FIN or RST flags.
I'm testing ipt-netflow 2.4 on Debian Jessie, with the 3.16.0-10-586 kernel. It seems to be working, but examining the exported records shows some inefficiencies. When dumping the records with nfdump, there seem to be a lot of single packet flows, even when the traffic obviously should not have been expired. For example:
This is not happening for all IPv6 flows, so I am confused what might be causing it. The above records show up sequentially in the data.
The configuration is mostly the defaults:
Is this a bug or expected behavior I am not understanding?