Closed candlerb closed 3 years ago
Hi @candlerb
It looks like nfdump does not support aggregation in statistics mode.
A query which combines -s
with -a
returns Command line switch -s overwrites -a
.
So it would be best to hide the fields in the statistics view.
This is with nfsen-ng master (27b7365c) under Ubuntu 18.04.
In the Statistics view, the aggregation buttons don't seem to do anything - they don't change the command sent to nfdump. To reproduce:
The nfdump command it generates is:
Then select "Global Aggregation - Bidirectional", and click "Process data" again, it gives exactly the same command:
Unselect Bidirectional, and select
IP Aggregation > Source > IP
then "Process data". Exactly the same result.If I enter a filter, like "net 10.0.0.0/8", that is passed to the backend - but the other buttons still don't do anything.
I have checked the traffic with tcpdump. With the "bidirectional" button selected I see
With
IP Aggregation > Source > IP
selected I seeClearly the correct flags are making it into the HTTP request, but for some reason the backend is ignoring them.
Aside: if you select "Statistic for" anything other than "Flow Records", then those buttons are greyed out anyway (and therefore not expected to do anything)