Re: n2disk to network drive?

Alfredo Cardigliano <[email protected]>
Newsgroups gmane.linux.ntop.general
Message-ID <[email protected]>
Hi Raoul
you should be able to run npcapextract on your network storage
as long as npcapextract is able to access both the timeline and the pcap files
and the timeline links have correct paths (the timeline is a tree of links to the
pcap and index files).
BTW, are you aware of the new ‘nxn' interface? This is a new GUI to run distributed
extractions, included in the nBox package. Please take a look at https://www.ntop.org/guides/nbox/usage/nxn.html
As of flushing data to disk, you have those 2 options you listed below, the first
one requires less efforts on your side as there is no need to broadcast a signal
to all the appliances, with the drawback that you can run queries on 10-min old
data (with the default configuration) or N-secs old data is you configure a max
duration (this depends on your use case).

Alfredo

> On 10 Apr 2018, at 22:45, Raoul Duke <[email protected]> wrote:
> 
> Hi,
> 
> Is it viable / recommended to write n2disk cache to (low latency) network storage?
> 
> I have multiple servers I would like to capture certain traffic profile on but then some time later be able to extract pcaps realated to certain application events.   My thinking is I'd rather not have to do the npacpextract "on box" and then have to work out how to copy them somewhere else on the network when I could just do the npacpextract directly off network storage.
> 
> Are there any limitations / gotchas I should be aware of if using npacpextract from a network attached cache while it is being written?
> 
> Also, this comes back to a question I asked the other day.  but assuming I wanted to npacpextract a certain pcap that happened between timestamps X and Y on port Z but I'm not sure yet if that data has been yet flushed to disk.  are my only options either to:
> 
> * use the [--max-file-duration|-t] $secs option and wait $secs after the associated application event until attempting to npacpextract
> 
> * force an explicit flush by sending a USR1 signal to the n2disk process. (this approach would be complicated if the cache is on network storage and the consumer wishing to run npacpextract is on a different machine than the n2disk process)
> 
> It seems like the first option is the least worst approach.  Can you suggest any others?
> 
> Thanks,
> RD
> 
> _______________________________________________
> Ntop mailing list
> [email protected]
> http://listgateway.unipi.it/mailman/listinfo/ntop

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEunYLiJIhvMrSEXzAm6qh6WCZ23EFAlrNzDAACgkQm6qh6WCZ
23GHWhAAqrpJtkBOwiPKjuUxZRDmh9WZ1vGahCOLTGk36EZSixpw53mOVG+TBlrg
ADqbTXb/bsJMfofdt9yxRVRXm9Ndl3QD95g+SBTvbbNY8rmBWAQ3nm6L1y1yBb5v
HQsvosjNOvXDDKMaHJbT7W2RDKDIcOrPkdGawZZh3AF2vBPd7Lm4pAo4A/aV9a7c
sMiLbgsdPIT3R2e8iDqYQOOPcwO5ns5IvDanZgwntcgpFEEWVBVLsTs6+VmbKsH9
l7du2cC7PDrU58z1RfOJQjjbKfiX7rD72JyiSo83gwKRisborES6irPJ8LcSrn91
KJ/N0r3KqYmcuuGehOFcio5WM1qlEHKCtKK/dXdO2Cvv5wsLCGfJZvb81UR+qBUi
pLA9EN/jKV5XriUH8RGTVGtCVhry6TNVYeqkn5xCS82N/047AebzZF2LZ5Tv96Lg
+rz/uJL3aiD/znKyuhSbf2EWb4BnCnHX+f5N8ococuTd5y5TqKwp5hb4aL0WHLIs
B3/hDrQHu7DKS5TXHs6Kq6r1lai/lrrSfY58p2aQJq+dHMM4JMH1gkVnMbo8nAdA
Q8LcEq7B0Mh7ZYY3qx0uaEx/1ezsub7L3tgjGRRxTODWzjMYpyAe2mn71mKnnFz4
hyb0CszpJL0GW4yoQNpJLnlOFNphQRK1L0RFKqrA3q1QAgsiUV8=
=nQ0m
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.