NetFlow v5 流记录格式

 

NetFlow v5 Record Format

The following fields are recorded in the NetFlow-5 record type:

NameDescriptionOffset

Field Length
in
Bytes

Source IPaddr IP address of the device that sent the flow 04
Destination IPaddr IP address of the destination device44
Next hop router IP address n/a84
Inbound snmpIFindex

SNMP index number that identifies the Inbound interface on the Packeteer unit:

1 Inside (built-in)
2 Outside (built-in)
3 Upper_Inside (upper LEM)
4 Upper_Outside (upper LEM)
5 Lower_Inside (lower LEM)
6 Lower_Outside (lower LEM)

122
Outbound snmpIFindex

SNMP index number that identifies the Outbound interface on the Packeteer unit:

1 Inside (built-in)
2 Outside (built-in)
3 Upper_Inside (upper LEM)
4 Upper_Outside (upper LEM)
5 Lower_Inside (lower LEM)
6 Lower_Outside (lower LEM)

142
Packet Count Number of packets in the flow 164
Byte Count Total number of bytes in the flow 204
Time at Start of Flow Value of SysUpTime when the first packet in the flow was seen (measured in milliseconds) 244
Time at End of Flow Value of SysUpTime when the last packet in the flow was seen (measured in milliseconds) 284
Source Port Port number of the device that the flow went out of 322
Destination Port Port number of the device that the flow went to 342
One pad byte n/a361
TCP flagsProtocol state (URG=32, ACK=16, PSH=8, RST=4, SYN=2, FIN=1). For example, a value of 27 indicates the flow had a SYN, ACK, PUSH, and FIN (2+16+8+1=27). 371
Layer 4 Protocol Type of layer 4 protocol. For example, ICMP=1, TCP=6, Telnet=14, UDP=17381
IP Type of Service (ToS) / Diffserv Value that designates special handling of traffic (precedence, delay, throughput, and reliability)391
Source Autonomous Sys ID n/a402
Dest. Autonomous Sys ID n/a422
Source Mask Bits Count n/a441
Destination Mask Bits Count n/a451
Two Pad Bytes n/a462

Certain fields (those marked with n/a in the Description column above) are applicable to routers, but not Packeteer units. These fields will always have a value of zero (0) in the NetFlow v5 records from Packeteer.

from:http://support.packeteer.com/documentation/packetguide/7.2.0/info/netflow5-records.htm

 
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值