Re: [IPFIX] [QUAR] Re: Export of long lived flow information
Andrew Feren <[email protected]>
| Newsgroups | gmane.ietf.ipfix |
|---|---|
| Message-ID | <[email protected]> |
Hi Paul, Interesting observation. The use of flow in these has never tripped me up the same way as the text in the original question. On 10/29/2012 07:56 AM, Paul Aitken wrote: > Should we change "this Flow" to "accounted in this Flow Record" > throughout the registry? > > I counted 67 instances. eg: > > > octetDeltaCount > > The number of octets since the previous report (if any) > in incoming packets for this Flow at the Observation Point. For this I think Flow is correct. I also think this highlights the distinction being made by people between Flow and Flow Record. If a Flow is bounded the same way (has the same start and end time) as a Flow Record then there can't have been a previous report for this Flow. The Flow and Flow Record would be the same. > > > tcpControlBits > > TCP control bits observed for packets of this Flow. > The information is encoded in a set of bit fields. > For each TCP control bit, there is a bit in this > set. A bit is set to 1 if any observed packet of this > Flow has the corresponding TCP control bit set to 1. > A value of 0 for a bit indicates that the corresponding > bit was not set in any of the observed packets > of this Flow. > > > flowDurationMilliseconds > > The difference in time between the first observed packet > of this Flow and the last observed packet of this Flow. Eep. Thinking about this is making me rethink my initial +1, but I do still think some rewording is needed. Using Flow Record works for deltas, but not for totals. I'm not sure yet what the right wording is. > > > ingressInterface > > The index of the IP interface where packets of this Flow > are being received. > > > egressInterface > > The index of the IP interface where packets of > this Flow are being sent. I think these last two are typically part of what defines a flow and won't change with out changing the Flow. So I guess Flow is as good as Flow Record. > > P. _______________________________________________ IPFIX mailing list [email protected] https://www.ietf.org/mailman/listinfo/ipfix