argus-clients 3.0.7.1 Cisco V9 flows

Carter Bullard carter at qosient.com
Tue Oct 2 09:21:11 EDT 2012


Hey Torbjörn,
Does this work ?
   argus -S cisco:x.x.x.x:9969 -s 1500 -w - | ra

Maybe we're not setting the snaplen correctly, passing partial packets to the netflow engine ?

Carter

Carter Bullard, QoSient, LLC
150 E. 57th Street Suite 12D
New York, New York 10022
+1 212 588-9133 Phone
+1 212 588-9134 Fax

On Oct 2, 2012, at 8:47 AM, Torbjorn Wictorin <Torbjorn.Wictorin at its.uu.se> wrote:

> hello,
> 
> I managed to capture netflow data with a workaround:
> 
> tcpdump -s 1500 -w - udp and port 9969 and dst host x.x.x.x | argus-3.0.7.1/bin/argus  -w -  -S cisco:- | \ 
> argus-clients-3.0.7.1/bin/ra 
> 
> /Torbjörn W



More information about the argus mailing list