Closed maksimtor closed 8 months ago
I see. Looks good, I am just curious. Is this common behavior?
I took as a point of reference how Wireshark decodes cflow and tested it on some data. It definitely can receive packet with 2 templates, it keeps length only in flowset, and if there are no templates to match with, it still shows headers and template id. So I think now we are closer to better practice
This is great I really appreciate your contribution
V9 parser seems to not work correctly in some of the more complex cases. I improved parsing a bit: