I have been using nfcapd to collect netflows and used to export them into a CSV using nfdump. This whole process has been working fine, however, I now have a requirement for which I need to switch over to nProbe (planning to use GTP plugin) to collect flows and dump them as CSV.
While dumping flows, I need to export current date with each flow, I have tried using --custom-fields attribute, but the problem is that it picks up the date when the collector was started and dumps that date. The date command is not evaluated every time a flow is dumped to CSV.
Is there a way to dump a dynamic attribute (e.g. datetime when the flow was received by the collector ) which is neither a standard attribute of the netflow nor a proprietary attribute.
Hi,
I have been using nfcapd to collect netflows and used to export them into a CSV using nfdump. This whole process has been working fine, however, I now have a requirement for which I need to switch over to nProbe (planning to use GTP plugin) to collect flows and dump them as CSV.
While dumping flows, I need to export current date with each flow, I have tried using
--custom-fields
attribute, but the problem is that it picks up the date when the collector was started and dumps that date. Thedate
command is not evaluated every time a flow is dumped to CSV.Is there a way to dump a dynamic attribute (e.g. datetime when the flow was received by the collector ) which is neither a standard attribute of the netflow nor a proprietary attribute.