Re: [c-nsp] Netflow vs SNMP
Gert Doering via cisco-nsp <[email protected]> Mon, 2 Oct 2023 08:36:08 +0200
| Newsgroups | gmane.network.nsp.cisco |
|---|---|
| Message-ID | <[email protected]> |
Hi,
On Mon, Oct 02, 2023 at 09:13:55AM +0300, Hank Nussbacher via cisco-nsp wrote:
> When comparing traffic stats with SNMP, Netflow stats always appear too low
> (see attachment).
>
> Opened a TAC case and their recommendation is to do 1:1 and I quote:
>
> "Irrespective of the rate at which the NP punts the records to CPU, exporter
> picks up a maximum of 2000 records at a time from the cache that are
> eligible for export (timers, network/TCP session events, etc). This is
> basically to avoid NetIO dropping the packets due to lack of b/w. When the
> exporter wakes up again, it repeats the same."
I fail to see why it would make sense to increase the number of flow
exports if their reasoning is "$machinery is busy, so, flow exports are
exported slowly"...
I do like 1:1 netflow, but the ASR9k (at least the linecards we have)
are not suitable to do that, alas - flow cache does not go high enough,
and NPU PPS is limited.
We currently do 1:10, which mostly works OK for our load, but we still
see a few
LC/0/0/CPU0:Oct 2 08:14:24.825 MEDST: nfsvr[280]: %MGBL-NETFLOW-6-INFO_CACHE_SIZE_EXCEEDED : Cache size of 1000000 for monitor v4mon has been exceeded
every day... (from what I understand, there should be enough LC memory
to go higher with that cache, but it cannot be configured).
gert
--
"If was one thing all people took for granted, was conviction that if you
feed honest figures into a computer, honest figures come out. Never doubted
it myself till I met a computer with a sense of humor."
Robert A. Heinlein, The Moon is a Harsh Mistress
Gert Doering - Munich, Germany [email protected]
_______________________________________________
cisco-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/
signature.asc
(application/pgp-signature, 630 B)
-----BEGIN PGP SIGNATURE----- iQGcBAEBAgAGBQJlGmTYAAoJEB2Cnv7KVigSH1AL/AwKwp18flAClcP96PvtrSEi VNOeTskXYIgL2GSvGzL0ryJgbhOfK4BvWQuDLixHZp9EwuaGdiUEocH867mNuIq+ jCEGxAxyV8V+m9faFu/EEQbTtPUOB6U4Fvq2jMcxCt9RHbFF5TkpuyubjeT9ywl5 25NIyTbgavxcgcE+reZ+r6j2tLNG737QYZeEMJc7/5AujLZH61/IziKYbCJP2hZ1 OqPqokIReo/1NV0RopPOOPWLOjVXSiXyITTyRAGQQEwIhDbaEcCNPLH1CKcvBuED FNLHztggZh4l5yJjrpOrTBvoxnUPJSTBAmw5QAx3QRMna/bGyzJubd27y5wM1W89 M96kU/viXnxgY+53/qk8lEmqM6XOt6XflTuiIwEAI4XcJFsyepR4C30XZA54CHzp PakoUdq0Qx5+GD4YKFQ8nWN5fGFV8EvIdTiHzS3INnpMGMgJ083/I8VM4aJexIcQ dOUQfwpP+UmX/2mcvX3bsei7Uq9EHS9HlZTjK7OnvQ== =k8XX -----END PGP SIGNATURE-----