Re: Kentik nprobes sampling reporting excessive packets

Jesse Alexander <[email protected]>
Newsgroups gmane.linux.ntop.general
Message-ID <[email protected]>
Luca,

Thank you very much.  I performed the nightly update but now I can't start it as a daemon because it removed /etc/init.d/nprobe and didn't add it back.

Welcome to nProbe v.7.5.170329 (r5697) for x86_64-unknown-linux-gnu

Can you please add it back?

Kind regards,

Jesse


From: [email protected] [mailto:[email protected]] On Behalf Of Luca Deri
Sent: Wednesday, March 29, 2017 3:52 AM
To: [email protected]
Subject: Re: [Ntop] Kentik nprobes sampling reporting excessive packets

Jesse,
I have modified this but I have forgot to reply, my fault.

Please download the latest nprobe and it will work. In the new release traffic upscale (i.e. x 160 multiplication) is not performed unless you use --upscale-traffic

Regards Luca

On 03/28/2017 01:54 PM, Jesse Alexander wrote:
Good morning (depending on where you are),

We are still waiting for a response to this.  Is this a known issue, or am I doing something wrong?  Or has there been an update with a fix?

Kind regards,

Jesse

From: [email protected]<mailto:[email protected]> [mailto:[email protected]] On Behalf Of Jesse Alexander
Sent: Monday, March 06, 2017 11:55 AM
To: [email protected]<mailto:[email protected]>
Subject: [Ntop] Kentik nprobes sampling reporting excessive packets


Hello,



We are using the version of nprobe to work with Kentik (nprobes) and we are seeing packets being reported incorrectly when using sampling.



$sudo nprobe -v

Welcome to nProbe v.7.5.170306 (r5675) for x86_64-unknown-linux-gnu

Copyright 2002-17 ntop.org

Build OS:      CentOS release 6.8 (Final)



Example script being used:

-q=A.A.A.A:6650

-n=X.X.X.X:9995

-n=Y.Y.Y.Y:2056

-V=5

-a=

-i=myri1-1

-S=160:1

-t=60

--if-networks=@/etc/cento/networks

-b=1

-Q=1

-u=1

--dump-stats=/var/log/nprobe/myri1-1-0_flows_stats.txt



With the above, when I perform a controlled bandwidth test using a traffic generator, the packets per second being reported to Kentik is roughly 350K.  The traffic generator is sending 2140pps of udp packets with 1460 byte payloads at a payload rate of 25 Mbps, so 25.9 Mbps with IP header.



We also sent the same data to another collector at the same time, and we saw exact same issue in the nfacctd data.



We saw that when we changed the sample rate, the pps was multiplied by that value, so in this case 160x (2140x160=342,400).



[cid:[email protected]]



[cid:[email protected]]







This is also evident in the attached png image of wireshark output from a captured packet.



[cid:[email protected]]



Can you please advise if this is a bug, and if so, the best course of action (use a previous version?), or if I am doing something wrong.



I also attached the images in case they are stripped out.



Kind regards,



Jesse








_______________________________________________

Ntop mailing list

[email protected]<mailto:[email protected]>

http://listgateway.unipi.it/mailman/listinfo/ntop

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop
image002.jpg (image/jpeg, 24.6 KB) - not displayed
image003.jpg (image/jpeg, 25.7 KB) - not displayed
image004.png (image/png, 167.9 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.