Java Exception int NFA 5502
Hi I'm trying to use NFA version 5502 on Linux FC5 machine. NFA starting from /etc/init.d/netflowanalyzer But time after time i'm getting this error, when clicking on an interface in dashboard window. type Exception report message description The server encountered an internal error () that prevented it from fulfilling this request. exception javax.servlet.ServletException: Can't connect to X11 window server using 'aei-nb:0.0' as the value of the DISPLAY variable. org.apache.jasper.runtime.PageContextImpl.doHandlePageException(PageContextImpl.java:825)
Report, sizing and hardware
Hi, We are quite satisfied with the feature and function of Network Analyzt during our evaluation. However, we have the following question: 1). Report: Is it possible to export any kind of report into PDF format? Since it is now seems that only the consolidated report can be exported to PDF. 2). Sizing In the evaluation, we have 6 routers with totally 19 interfaces. However, we have near 400 interfaces that would like to be monitor in our production environment. Is it possible to use just one single
Is it a bug?
Dear Sir/Madam, We are evaluating your website demo for netflow analyzer. But we found some bugs which we considered as. Please refer to the attached picture. When we select last hour or last two hours for application analysis. The result has some problem. For example: In application analysis, the analysis result have data record but no chart. Why? 2.jpg - the right result for current hour 3.jpg - the error result for last one hour 4.jpg - the right result for last two hour Please confirm whether
TCP APP display in Interface Group
I have set up an interface group to combine the WAN interfaces of two routers either of which could be used for traffic. This works fine. However, I am seeing the entry TCP_APP as a fairly heavy application. When I click on TCP_APP it displays the sessions involved with port *. However, when I click on the small box that appears after TCP_APP it says there is no data to display. I have set up multiple interface groups and this happens for all of them. When I go in via a single interface on a single
Frame Relay Traffic Stats
I have just installed and licensed version 5 of the Netflow Analyzer and on Frame Relay PVC's am only capturing out traffic. Please can you tell me why. Also teh Quicklink is not working on the "All Devices" Page Thanks in advance for your assistance.
Time Stamps
Hi, In the details for Application, Source, Destination and Conversation the details of traffic flow are shown, however, no time is given for each item. At the top of the page it is shown that the data is for the previous hour but does not show what the time is specifically. Is this something that can be viewed?
IP Groups
You have now changed the display of IP Groups so that they come out in alphabetical order and this is great. However, I added an IP group which contained an array of IP address ranges. I added them in IP address order. Now when I display the IP group, the constituent IP address ranges come out in a different order. Can you change Netflow Analyzer so it lists the IP Address ranges in ascending order? Can it be made to do this no matter what order I originally added them in? Also, because I have to
Change title in browser windows
Hallo, i want to customize the title in the browser ("Manage Engine NetFlow Analyzer 5"). I have four installations of Netflow-Server running - in all browser-windows the same title is shown Thanks Tom
Analyzer is no longer classifying Http port 80
I have created a couple of custom apps for our internal HTTP traffic but now our external Http traffic is showing up as unclassified TCP. 10.150.101.76 205.192.36.135 TCP 1148 80 7.28 KB 10.35.100.76 205.192.61.10 TCP 1319 80 14.47 KB
i have forgot my admin password,how shall i do?
please help me,i don't know what i can do.
clean old records from flow database
Hi How can I clean the old records from flow database (for example 6 month ago) ? Thanks Alex
Service Dies; Tries to restart but kills itself!
Hi all, Netflow was running fine, however it appears to have not responded to one of its own checks, tried to terminate itself, and restart the process. However, I have found that Netflow doesn't like to terminate the java process correctly and leaves it defunt and still holding up the ports which it should have released back... This is the errors we see in the wrapper log... INFO | jvm 1 | 2006/10/16 10:32:50 | ServerContainer [CREATED] INFO | jvm 1 | 2006/10/16 10:32:52 | NetFlowAnalyzer [CREATED]
Bugs in scedule reports
Hello, when I create an automatic report, and i want to do some changes on it, theres an update button missing! So i have to delete the scedule and create it new. Can you fix this? greetz
alert based on ToS and BW
Can alerting/reporting be setup to use ToS and bandwidth. IE I'd like to create an alert if traffic marked as immediate is exceeding 10% of available bandwidth. Also I'd like to create reports based on TOS. This is for QoS reporting.
Delay in reports
Hi, My company is now evaluating the NFA 5.5 and have some questions on the reporting. The reports are showing not very real time at all. The NFA keep receiving the netflow data from the routers but it always have around 20 minutes delay, i.e. cannot show the latest 20 minutes activities. I have tried to set a shorter active timeout to 1 minutes but the problem still exist. And the problem is also router model independent. Is there any setting that I have missed in order to see the latest activities?
Scheduled Reports - Don't zip?
How do I prevent the Scheduled Report's from being zip'd when e-mailed? I'd rather it just sent the file in its original .pdf format since we block .ZIP e-mail attachments.
Please Set the Correct Router Time
Hi have just upgraded from version 4 to 5.5 and now i dont get any stats and a error message on all devices saying please set correct router time. This was working fine before upgrade. Thanks Mark
I have forgot my admin password,how shall i do?
please help me,i don't know what i can do.
RHEL3 / NFA 5.5 - IP groups and performance
I have seen a few posts regarding the performance of NFA with many IP groups. I am looking to use this product for the management and monitoring (and indeed billing) of bandwidth over 4096 IP addresses, shared between approximately 150 clients. This means I plan on defining 150 IP groups. Each group will have between 4 and 256 IP addresses. Mostly they are allocted in logical blocks (e.g. /30 or /27 blocks), but approximately 30 IP groups are non-sequential scatterings of IP addresses that need to
DB Backup and Restore
I am conducting an evaluation of Netflow Analyzer 5.0 for my organization. We are looking for a netflow collector that allows us to view detailed data flow on our networks, determine the impact of new software on our network and store and recall this data for later analysis. I understand that in NFA 5.5 the raw data is retained for 1 Month with 1 minute granularity. Is it possible to backup the raw data and later restore it with the intent to view the 1 minute granularity say a year down the road?
Collecting flows from a Cisco Catalist 6506 using dCEF
I want to collect flows from a Cisco Catalist Multilayer Switch 6506 but NFA only shows inbound traffic on all interfaces. The Cisco Switch is using dCEF (Distribuited CEF). Is there any specific config for this equipment..? This is part of my running-config: ip flow-cache timeout active 1 ip route-cache flow (on some interfaces) ip flow-export version 5 ip flow-export destination xxx.xxx.xxx.xxx 9999 Thanks in advance... Israel.
NFA5.5 Demo Crashing
Hi I am running the NFA5.5 demo on RHEL3. Occasionally we find that demo crashes. Upon restart we get the "unclean shutdown" error message. In the JBoss server error logs, I have found the following output prior to the crashes: [00:17:16:636]|[10-18-2006]|[SYSOUT]|[INFO]|[28]|: Error occured while executing process :: | [00:17:16:636]|[10-18-2006]|[SYSOUT]|[INFO]|[28]|: Record count of table is well below 250000| [00:17:16:636]|[10-18-2006]|[SYSOUT]|[INFO]|[28]|: at com.adventnet.netflow.utils.dm.SiblingPreProcessor.executeProcess(SiblingPreProcessor.java:73)|
Netflow Version 9 error message and NAT support
I have recently upgraded my free version of NFA to 5.5 and then enabled Netflow Version 9 on my router. I am now getting a message every so often in NFA: V9 flows of unknown template are received from [x.x.x.x] Are there any additional changes I need to make to the router? I also read that Netflow 9 has support for NAT (amongst other things such as MPLS). I have an issue with the netflow stats on a NAT interface (ADSL Dialer) whereby the egress stats are shown on the Dialer interface and the ingress
IN OUT SOURCE DESTINATION
In addition to the earlier sent, please can you explain IN and OUT in relation to Source, destination? My own understanding is as below From my workstation going out to the Internet for e.g. hotmail I am the source and hotmail is the destination When the ISP is sending the emails I receive to me, then the ISP is the source and I am the destination. IN and OUT. IN Coming in to the interface, so all the network coming into our LAN from the Internet is coming IN and When we go out to surf, then we are
Router list order
Is there a way to change the order in which the routers are listed in the interface view? i.e. alphabetical order?
Netflow display
I am new to this and have installed the v 5.5 which have installed successfully and using a C2800 router. We have a 2MB Internet Line but when I look at the stats, i see total on 10.2MB for IN and 98.91 MB for OUT. Please can this be explained? What I really want to do is know how much of the 2MB line is used by each protocol or network going via the 2MB Internet Line. Also the traffic comes in byes. Is there a way I can change it to MB so that it is more understandable by me and most importantly
Can't get NFA to start to evaluate
Same symptoms as posted here by other users. [root@hh-lab01 bin]# ./run.sh ================================================================================ JBoss Bootstrap Environment JBOSS_HOME: /NetFlow JAVA: ../jre/bin/java JAVA_OPTS: -server -Xms128m -Xmx256m -Dprogram.name=run.sh -Djboss.server.type=com.adventnet.j2ee.deployment.system.AdventNetServerImpl -Djboss.deploy.localcopy=true -Djboss.boot.library.list=log4j-boot.jar,jboss-common.jar,jboss-system.jar,AdventNetDeploymentSystem.jar,commons-logging.jar
Questions.....
Please help with the requests below. When I do a show interface on the router serial, it shows BW2048Kbit SO I have changed the EditInterfaceName to 2048000 bits / sec for speed. Is this correct as it still comes up with the yellow exclamation mark in the Utilization tab of the traffic The active time out is also set as ip flow-cache timeout active 1 So everything seem right but it is still coming up as not correct with the yellow box. 2. I have changed the time zone and time on the router, but the
Applications
I have just installed Netflow Analyzer 5002 and I want to delete all the applications defined in it and start with a new smaller subset of just the ones that we use. It will be much quicker to start from nothing. Is there a quick way of doing this without going through the web page deleting one at a time?
95th percentile different to OpManager's?
Hi, I'm a little confused by the 95th percentile watermarks in NFA5.5 and OpManager. NFA says this: Category Total Max Min Avg 95th Percentile Traffic IN 7459.61 MB 6.14 Mbps - 984.76 Kbps 4.01 Mbps Traffic OUT 7563.77 MB 5.25 Mbps - 998.51 Kbps 4.1 Mbps For the same period on the same interface, OpManager says this: Max (kbps) Min (kbps) Avg (kbps) Current (kbps) 95th Percentile (kbps) In 4025.97 148.52 1022.03 539.81 863.35 Out 4124.0 74.83 1054.95 639.26 893.03 I can understand reasons for the
Stats thru None Cisco device
Is it possible to use this product for none Cisco devices using standard SNMP?
Interface Name in Netflow
I would like that Netflow shows interface name instead of ifindex1 ifindex2 etc. Not sure what makes this, some routers gives correct name. I do yous Netflow 5.5 with a Cisco 2821 12.4(9)T and subinterface with VLAN like gigibit 0/0.20 Does this has anything to do with "snmp-server ifindex persist"?
incongruity in Conversation reports
Hi all, Let say we are on Int f0, Conversations Tab, IN, last hour report, if I group by Source IP, I see for example: 172.16.1.204 Any Any Any Any 72.12 MB So, in this scenario, I choose now "last day report", instead of "last hour report", I get this: 172.16.1.204 Any Any Any Any 31.65 MB My question is, Is it possible that "last hour report" is bigger than "last day report"? I think it's suppose that "last day report" be bigger than "last hour report" I'm running NFA 5.5 on linux regards Israel
Netflow v9
Hi, What are the benefits of exporting v9 flows to NFA, compared to v5 flows? Does NFA do anything with "special" with v9? many thanks, alec
CPU utilization
Hi, I wanted to test NetFlow on a Cisco 3661 with 2 E1 card with 46 channel used and 5 Serial interface. Before i go ahead with the test, what could be the CPU and RAM memory load caused by Netflow for one and all interface. Regards, Kern
NFA database maintenance!
Hi Raghu for your soon answer to my question about Conversation traffic.. I have another question: Is there some way to make some Maintenance of the database? my netflow folder is about 7 GB now..! regards; Israel
IN traffic 0%
Hi, Everything seems fine, but the IN and Out traffic shows 0% even though there is traffic on it. Can anyone explain what that percentage bar means? regards, Krishna
Ip Group and raw data!
I create an Ip group: MSN Speed: 1000000 bps Description: MSN Server IP Address(Netmask) : 172.16.1.204 (---) Port (Protocol): All Associated Interfaces: 172.19.81.200 (Prim Sierra, Sec Sierra) My question is: All hourly, daily, weekly reports are from aggregated or raw data? regards; Israel
doubt about granularity!
I don't want to bother you with my questions, but I want to understand what I'm looking in NFA reports, please can you explain me what is the meaning of granularity when we use aggregated data? I mean, for example: 172.19.81.200 --> Prim Praga --> Conversation IN --> "last day report" Any 172.16.1.204 Any Any Any 5.41 MB You told me "last day report" use aggregated data, can you explain me what's the meaning of this 5.41 MB? is it a "round up" of the 24 hours traffic? I have set Record Count: 100
No Router is currently exporting NetFlow packets
My sniffer shows UDP 9996 packets making it to the NF5 server, however I still get this error: No Router is currently exporting NetFlow packets to NetFlow Analyzer. I've been refreshing this screen for 2 hours. I vaguely remember having to configure a group to get this working the first time... that may have been another netflow product. I had this working a few weeks ago, uninstalled NF5, then after reinstalling NF5 today now it will not recognize the netflow packets. Router#sh ip flow exp Flow
Next Page