ntop / nProbe

Open source components and extensions for nProbe
http://ntop.org
GNU General Public License v2.0
1.62k stars 44 forks source link

nprobe not listening on 2055 #557

Closed sfedu-admin closed 6 months ago

sfedu-admin commented 1 year ago

Hi! Im using nprobe in collector mode:

-n=none
-i=ens18
-3=2055
#-s=1536
#-t=60
#-d=60
#-a=0
#-e=1
#-B=10
#-w=128000
#-z=0:0:0
#-S=1:1:1
#-E=0:0
-g=/var/run/nprobe-ens18.pid
--zmq=tcp://127.0.0.1:1234
#--vlanid-as-iface-idx=none
#-T=%FIRST_SWITCHED  %INPUT_SNMP  %IN_BYTES  %IN_PKTS  %IPV4_DST_ADDR  %IPV4_SRC_ADDR  %IP_PROTOCOL_VERSION  %L4_DST_PORT  %L4_SRC_PORT  %LAST_SWITCHED  %OUTPUT_SNMP  %OUT_BYTES  %OUT_PKTS  %PROTOCOL  %SRC_TOS  %TCP_FLAGS
-V=9
--dump-stats=/var/log/nprobe/ens18-0_flows_stats.txt

This config working flawlessly few days ago. Now I dont see 2055 udp port listening:

root@ntop:~
# netstat -tulpn |grep 2055
root@ntop:~

Here is nprobe log file:

Dec 26 14:56:18 ntop systemd[1]: nprobe@ens18@0.service: Succeeded.
Dec 26 14:56:18 ntop systemd[1]: Stopped nprobe extensible NetFlow v5/v9/IPFIX probe/collector for IPv4/v6 on ens18@0.
Dec 26 14:56:22 ntop systemd[1]: Starting nprobe extensible NetFlow v5/v9/IPFIX probe/collector for IPv4/v6 on ens18@0...
Dec 26 14:56:22 ntop systemd[1]: Started nprobe extensible NetFlow v5/v9/IPFIX probe/collector for IPv4/v6 on ens18@0.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:5478] Reading configuration file /run/nprobe-ens18@0.conf
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [plugin.c:178] No plugins found in ./plugins
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [plugin.c:186] Loading 23 plugins [.so] from /usr/lib/nprobe/plugins
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:5247] Valid nProbe Pro [ntopng Enterprise L License] license found
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:5803] Disabling flow cache during collection
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:7453] WARNING: The output interfaceId is set to 0: did you forget to use -Q perhaps ?
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:7456] WARNING: The input interfaceId is set to 0: did you forget to use -u perhaps ?
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:7477] Using ZMQ sourceId 486333327
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:7541] WARNING: --enable-collection-cache can be used only in collection mode and with -i none: i>
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:7548] Welcome to nProbe v.10.0.221224 for x86_64-pc-linux-gnu with native PF_RING acceleration
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:7566] Pro [ntopng Enterprise L License] Edition running on Ubuntu 20.04.5 LTS
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:7567] Current limits [4 ZMQ exporters][4 collector devices]
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:7578] SystemId: L90128F741C001090--U90128F74CAB98B31--OL
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:7651] Sample rate [packet: 1][flow collection/export: 1/1]
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:9627] Using template %IN_SRC_MAC %OUT_DST_MAC %INPUT_SNMP %OUTPUT_SNMP %SRC_VLAN %IPV4_SRC_ADDR >
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:9629] Using NetFlow Packet Payload Len: 1472
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'DNS_QUERY': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'DNS_QUERY_TYPE': Pro version does not include plugin>
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'DNS_RET_CODE': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_URL': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_SITE': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_METHOD': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_RET_CODE': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_USER_AGENT': Pro version does not include plugi>
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'DNS_QUERY': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'DNS_QUERY_TYPE': Pro version does not include plugin>
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'DNS_RET_CODE': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_URL': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_SITE': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_METHOD': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_RET_CODE': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_USER_AGENT': Pro version does not include plugi>
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'NPROBE_IPV6_ADDRESS': Pro version does not include p>
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'DNS_QUERY': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'DNS_QUERY_TYPE': Pro version does not include plugin>
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'DNS_RET_CODE': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_URL': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_SITE': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_METHOD': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_RET_CODE': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_USER_AGENT': Pro version does not include plugi>
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'NPROBE_IPV6_ADDRESS': Pro version does not include p>
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'DNS_QUERY': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'DNS_QUERY_TYPE': Pro version does not include plugin>
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'DNS_RET_CODE': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_URL': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_SITE': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_METHOD': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_RET_CODE': Pro version does not include plugins.
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [template.c:3488] WARNING: Unable to locate template 'HTTP_USER_AGENT': Pro version does not include plugi>
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [plugin.c:1196] 0 plugin(s) enabled
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:10162] Each flow is 326 bytes long
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:10163] The # flows per packet has been set to 3
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:10166] IP TOS is ignored
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:10934] Flow export type (-T): bidirectional flows
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:11139] Flows ASs will not be computed (no GeoDB files loaded with --as-list)
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:11171] Flows will be exported in NetFlow 9 format
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [util.c:6196] Initializing ZMQ as server
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [util.c:6275] Successfully created ZMQ endpoint tcp://127.0.0.1:1234 with sourceId: 486333327
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:11388] Not capturing packet from interface (collector mode)
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [util.c:5091] nProbe changed user to 'nprobe'
Dec 26 14:56:22 ntop nprobe[78650]: 26/Dec/2022 14:56:22 [nprobe.c:11680] nProbe started successfully
sfedu-admin commented 1 year ago

ntopng Enterprise L v.5.4.221224

lucaderi commented 6 months ago

Sorry for the late reply. You cannot use -3 and -i simultaneously. Please start two nprobe instances: one for flow collection and one for packet capture.