#Open source NetFlow collector
##Over ten years players
###nfsen family - nfpcapd
nfsen has very stable and well-accumulated feature set. It provides full-stack of NetFlow feature. NetFlow collector daemon nfpcapd
, flow dump file operation tool nfdump
and Web front-end nfsen
. Community is still avtive.
###ntop-ng family - nprobe
###pmacct family- pmacctd
Momory table is something that I want to try.
##New commers from log collection domain
- fluentd + netflow plug-in
- peformance: Saturate around 600fps. Basically one fluentd process can use one CPU core and around 600fps, it keeps 99% CPU core usage.
- logstash + netflow plug-in
- graylog