NetFlow Collection with nfcapd, nfdump and NfSen - 夜莺博客

NetFlow Collection with nfcapd, nfdump and NfSen

When a link saturates or a host starts scanning, counters alone tell you nothing about who is responsible. Flow telemetry answers that, and the nfdump toolset remains the cheapest way to run it: nfcapd collects NetFlow v5/v9 and IPFIX into rotating binary files, nfdump filters and aggregates them from the shell, and NfSen adds a web front end. Everything runs on one modest Linux host with no licence. This guide covers a production-shaped single-node deployment.

1. Install from source

sudo apt-get install build-essential autoconf libtool pkg-config libbz2-dev
wget https://github.com/phaag/nfdump/archive/v1.7.4.tar.gz
tar -xvzf v1.7.4.tar.gz && cd nfdump-1.7.4
./autogen.sh
./configure --enable-nfprofile --enable-nftrack
make && sudo make install && sudo ldconfig

Build with --enable-nfprofile --enable-nftrack if NfSen is planned, since its PortTracker plugin depends on them. Practically every tool that previously needed an explicit flag is now built by default.

2. Start the collector

mkdir -p /flow/router-core1
nfcapd -D -S 2 -w /flow/router-core1 -p 2055 -B 200000 -l /var/log/nfcapd.log

-S 2 rotates a file every two minutes, -p 2055 sets the UDP listen port, -B increases the socket buffer to survive bursts. Point the exporter at the collector, and confirm packets arrive before touching filters: tcpdump -ni eth0 udp port 2055. The exporter side is covered in Cisco Flexible NetFlow Configuration Step by Step.

3. Query flows with filters

nfdump -r /flow/router-core1/nfcapd.current -n 20 -s srcip/bytes
nfdump -R /flow/router-core1 -t 2026-09-29 -s dstip/bytes -n 10
nfdump -R /flow/router-core1 'src net 10.20.0.0/16 and proto tcp and port 445'
nfdump -R /flow/router-core1 -A srcip,dstport -s bytes -n 25

The filter language matches on address families, protocol, ports, AS numbers, next hop, ToS and TCP flags, and aggregation via -A turns raw records into top-talker tables. Keep the collector's clock synchronised -- flow timestamps are only as trustworthy as NTP.

4. Lifecycle: rotation, expiry and retention

nfexpire -p /flow/router-core1/ -s 4 -e 90d   # 4 GB max, 90 days of data
nfexpire -p /flow/router-core1/               # show current usage

Run nfexpire from cron. Flow data grows faster than you expect; without an expiry policy the collector fills its disk and stops recording exactly when you need history.

5. NfSen front end (optional)

cd nfsen-1.3.11 && cp etc/nfsen-dist.conf etc/nfsen.conf
# in nfsen.conf: $BASEDIR, $HTMLDIR, $WWWUSER, %sources
sudo perl install.pl etc/nfsen.conf
sudo /etc/init.d/nfsen start

Each entry in %sources becomes one channel with its own colour and UDP port, and nfsen reconfig rebuilds channels after edits. The web UI renders RRD graphs per profile, per protocol and per AS.

Verification checklist

  • nfcapd -l or the log file should show new files appearing every rotation interval.
  • nfdump -r ... -c should return a non-zero record count for the last window.
  • Compare a busy hour against interface counters; a large mismatch means sampling or a missing exporter. If you need capability comparison between telemetry types, see sFlow vs NetFlow vs IPFIX: Network Monitoring Protocols Compared.

原文链接:https://github.com/phaag/nfdump/blob/master/README.md