Netflow 5.5 EA Reports
I want to schedule a report that will be issued at lunchtime and summarises the morning's activity. Is there a way of doing this? There seems to be a time filter available but this only appears when the 'Previous 24 hours' option is selected. However, if one sets it it seems to be ignored or does strange things to the data. I just tried two exact same reports, one with the filter and one without and the results were not the same. It is not mentioned anywhere on the help page. What does this parameter
Alerts
Hi, I have configured an alert profile to receive alerts when a link utilization exceeds a certain threshold. The utilization percentage I am getting in the alert email is not explainable. I assume the number should be something between the threshold number I set and 100% however the number I am getting in most cases is over 1000% Message : OUT Utilization router(Tunnel20) is 1402% AlertProfile Name: VPN Link Util AlertProfile Desc : Severity : WARNING Device name : gw-fiber.aub.edu.lb Interface
Netflow 5.5 EA Interface Groups
I have defined an Interface Group but when I now go to define an IP Group it does not give me the option of selecting the Interface Group. I have to select all the individual interfaces across all the routers all over again. Now I go to User Management thinking I will give a user this Interface Group to view. There does not seem to be a way. Is there a way of using Interface Groups for these purposes?
No graffs
I have just installed Netflow Analyzer, and i am receiving data from my routers interfaces( i have that green sign infront of interfaces name). I have added Device Group and ip Groups, but i can't see any graff nor data for the Inerfaces in the Group and ip Groups. Help.
NetFlow on 3700 Series
We have a need to monitor a 3740 router but have not seen mention of the 3700 series in the NetFlow documentation. Are 3700 series routers supported? Thank you. -Eric.
Rename Interfaces on netflow web console
We have installed the Netflow analyzer and have configured all the routers accordingly, Is there any way to rename/description the interfaces on netflow analyzer web console so we can have the locations name / description instead a gerneric name. i am seeing many interfaces on netflow web console showing Ifindex1 Ifindex2 Ifindex3 Ifindex4 What does the above means ?
Router Clock Synchronisation
I have just experiemced a strange problem and was looking for an explanation. I have six routers each with two interfaces managed. Two of these routers were showing the little exclamation mark saying that the time was not synchronised. On checking inside the routers it appeared that the timezone had not been set correctly by the owner. It was set to UTC but the time was one hour ahead of UTC (ie. on BST). The time has now been set back one hour. However, now all the interfaces on all the routers
TWO THINGS !!
hELLO, I am using first time NetFlow Analyzer and found it splendid, one 2 points i am stucked these are as: 1. Can i Analyze me servers using NetFlow Analyzer (I have Linux, Solaris and Windows) servers in my Network. as i didn't find anything for these. 2. I hav entered all my routers in it except my internet router, bcoz it is not added up in it. donno wat the problem is. i have enable netflow on all interfaces. but when i do eneterd in IP group and give IP there after that in select devices i
how to add device group
I download the demo software,and when I wanna add new device group,it will show "No Device Groups have been currently configured",why?
Running NFA 5 and other Java/MySQL applications
Dear tech. support friends, With reference to your product, I'd like to let you know that I am currently evaluating it. I have found an issue that my affect my customer's acceptance regarding NFA 5. Now at this time I�ve been testing it over Microsoft Windows Platform. They have a few Juniper WX-20 (formely known as Peribit SR-20) devices that are able to export NetFlow data to a system such as the NFA 5. This Juniper/Peribit solution is managed by a software named "CMS", which uses MySQL and Java.
Slow reporting
I am evaluating NetFlow Analyzer (trying both 5.0 and 5.5EA) and currently have it setup to collect netflow information from a 1 gigabit interface which has constant flow of 200-350Mbps (anywhere from 2000 to 3000 flows per sec). This running on a Dual P4 3.2GHz with 2GB RAM. I have made the suggested tweaks to increase the memory alloted to MySQL: --key_buffer_size=720000000 --innodb_buffer_pool_size=848000000. Pulling up most reports (especially the IP source/destination, any of the protocol breakdowns
Netflow Analyzer 5 service does not start
Hi, I have Windows 2003 Server R2 Build 3790 with latest patches. I downloaded evaluation version of Netflow Analyzer 5 (today). The installation has no problem, but when trying to start Netflow Analyzer service, the progress bar comes about to 17%, and disappears. Also the tray icon disappears as well. When I check services, I see the service is not running. I try to start it manually, but same thing happens. It waits for 17% and disappears, and service status is "stopped". http://localhost:8080
Netflow only showing outgoing IN traffic
I've just got netflow analyzer installed about an hour ago, and this tool rocks. I've noticed however that my internet serial interface is only showing IN packets and not OUT packets. I'm sure it's something I've got configured wrong, so I thought I would ask the NA experts here. Thanks! Matt
Backdating IP Groups
I have just added a new IP group with an IP range in it for a couple of interfaces on a couple of routers. It is starting to collect data fine. However, what I need is an option to tell Netflow to use all the data that I have already (raw data) to backdate this IP Group information. One thing that always seems to happen is that I am asked to see what a particular IP address or site was doing (in the past). Obviously I have the raw data but using troubleshooting is so slow. Every time I change what
Analizing a circuit with different upload/download rates
Hello I would like to know if there is a way to tweak the NetFlow Analyzer to calculate the utilization of a serial interface based on different upload/download rates. The circuit I want to analyze has a download bandwitdh that is not limited, and can achieve bandwidths up to the full access circuit speed of 2mb, but the upload is limited to only 768K. Therefore, if I set the port speed to 768k, and if the download rate its greater than 768k, from its perspective download link utilizations exceed
Application Mapping
I am trying to categorize our http traffic using Application mapping, I've done the following 80 TCP 10.0.0.0 Netmask: 255.0.0.0 http_VAC-Internal 80 TCP 167.74.0.0 Netmask: 255.255.0.0 http_BlueCross 80 TCP All http unfortunately 80 TCP 10.0.0.0 Netmask: 255.0.0.0 Vac-internal-http does not seem to work but 80 TCP 167.74.0.0 Netmask: 255.255.0.0 http_BlueCross does.
Alert based on application exceeding BW threashold
I've set up an alert profile to send mail messages when any application utilizes more then 30% of the bandwidth. When the mail message comes in it doesn't identify what application/port is has exceeded the threshold. Would it be possible to include this in a future release? Message : Total Utilization vadsqc-gtrt060(Serial0/0/0.1) is 80% AlertProfile Name: test3 AlertProfile Desc: alert based on any app using 30% of BW Severity : WARNING Device name : vadsqc-gtrt060 Interface name : Serial0/0/0.1
Where's support
I've sent multiple emails to support but have not received any responses. You make a good product, but if you can't properly support it, why should we buy it? Looks like you 'll be losing another customer to Crannog.
Unable to modify Shecduled Reports
After creating a couple of test reports and saving them I am unable to go back in and modify them. Is this a known issue with this latest release or is this not an available feature? Stephen
Customising Dashboard View
We are using Netflow version 5 and would like to run a customised Dashboard view on a wall mounted screen in our ops room. Currently we have to keep refreshing and highlighting different devices to view the info we require and if we exceed the timeout we have to log into Netflow again.
How to remove a monitored router and historic data (5.0)
We are seeing traffic utilisation reports showing >100% usage. Bandwidth/link speeds are correct. I believe this may be because our routers are configured for "timeout active 5" and not "timeout active 1" as per your recommendation. I want to remove a router from Netflow to reset the data, to make sure the new "timeout active 1" setting has taken effect and resolved the percentage problem. I have tried disabling Netflow on the router, unmanaging and then deleted the router under License Administration.
nprobe switches
I am using nprobe to trial Netflowanalyzer and I was wondering what the recommened switches are for timeouts etc. Thanks. -t <dump timeout> | It specifies the maximum (seconds) flow lifetime | [default=120] -d <idle timeout> | It specifies the maximum (seconds) flow idle lifetime | [default=30] -l <send timeout> | It specifies how long expired flows queued in nprobe for de livery | are emitted [default=30] -s <scan cycle> | It specifies how often (seconds) expired flows are emitted | [default=30]
No Router is currently exporting NetFlow
We are evaluating the Netflow Analyzer 5. The problem we have is: from the NA web Gui we can't get the router showed. We are running cisco 45010R (12.2(18)EW) with Netflow card WS-F4531, and configured to export netflow to the NA server like this: ip flow ingress ip flow-export version 5 ip flow-export destination IP NA SERVER 9996 I use a sniffer and can see udp packets from the switch to NA server on port 9996, but form the GUI, it always said ' No Router is currently exporting NetFlow packets
Configuring Threshold for Mail alerts
Hi, I have a query that if i configure Alert for any application or protocol, along with thresold. Do i get alert specifying utilization on that specific port or for the complete link. If it is only for particular application then where we can modify the same. ALert looks like below Dear Administrator, This is an automated mail generated by the ManageEngine NetFlow Analyzer, to inform you of following event. *************************************************************************************** Message
start mysql server failed
I have installed netflow analyzer on windows 2003 server and run as administrator. on start , it said start mysql server failed. i find the error log file as below. error log 060721 22:05:37 InnoDB: Operating system error number 32 in a file operation. InnoDB: See http://www.innodb.com/ibman.html for installation help. InnoDB: See section 13.2 at http://www.innodb.com/ibman.html InnoDB: about operating system error numbers. InnoDB: File name c:\progra~1\dell\openma~1\networ~1\oware3rd\mysql\4_0_13\ibdata\ibdata1
this is my first time
No Router is currently exporting NetFlow packets to NetFlow Analyzer. ... how do i allow my router to export packets to netflow analyzer?
NetFlow Analyzer 5.5 EA Available
We are glad to announce the availability of NetFlow Analyzer 5.5 Early Access. NetFlow Analyzer 5.5.0 (Build 5500) includes the following: Major Features 1. Reporting on NBAR statistics 2. Support for NetFlow V9 3. Automatic Scheduling and emailing of reports 4. Associating IP address in application mapping (in addition to the port and protocol available now) 5. Ability to create interface group - ability to group interfaces together and monitor traffic 6. Reporting on ToS and TCP_Flag Minor Features
Application-mapping / port range
I am currently running a demo of the product, and I am having a few challenges identifying Voice packets, specifically I need to id rtp streams which use dynamic UDP ports (in the range of 22800-32767). Is there a way to add application based identification similar to nbar or maybe have an option to add apps by port range? Or if you can recommend maybe the best way to go about this, thanks allen
"Automatic" application recognition
Hi, in NFA, is application recognition done solely by using port/protocol mappings, or is there any other mechanism used to do this (statistics about flow characteristics, a.s.o.)? This would be very useful and supportive for recognizing new applications in the network without having to introduce new traffic by hand. Thank you, Melitta
Monitor Bittorrent Traffic
My Cisco router 1841 will detect Bittorrent traffic correctly using NBAR whether or not it uses the standard 6881-6889 port. However, when viewing the application report in Netflow Analyzer 4, pretty much all bittorrent traffic goes under the TCP_App category, very few actually went to the bittorrent category. Is there anything I can do or configure so that it will capture non-standard bittorrent traffic to the right category?
Tftp Server: java.lang.ArrayIndexOutOfBoundsException
In webnms4.7 ,Tftp Server can not support chinese file name ,it always print error: Tftp Server : java.lang.ArrayIndexOutOfBoundsException and Tftp Server is down! What i should do?
NBAR Reports
Hi, I have installed NFA 5.5 to use the new NBAR feature. For testing I have enabled NBAR on two Cisco 2811 routers. The sh ip nbar protocol-discovery is working fine from the router CLI however when I try to view the NBAR report from NFA I get no data is available. Thank you Ramzi
Netflow Stats on Router
how can netflow stats i.e top talkers, top bandwidth utilization etc be monitored on router itself(i.e without importing to any destination server )
NetFlow Analyzer EA 5.5 - NBAR support
Hi guys, why is SNMP write access reqd for NBAR support? and what exactly will the app (NFA) be trying to do on the devcies with this write access? thanks, Marty.
Problem - Statistics with 30% OTHERS traffic.
I'm trying to generate report with NFA. Interface/destination traffic (in my case this is Internet traffic received by local users). Every time i generate statistics for last hour I can see traffic for each local IP and there is no "others" in report. But everytime i generate statistic for more than last hour (e.g. for last day/last week) i can see in report all my local IPs (about 15-20 records) and "Others" with traffic part 10-35%. (I've got only 20 local users ) If i use "TroubleShoot" to generate
Netflow Stats on Router
how can netflow stats i.e top talkers, top bandwidth utilization etc be monitored on router itself(i.e without importing to any destination server )
lionkAsService.sh help
I am running NFA on SLES (I know it's not supported, but my hands are tied). I want to setup NFA to run as a Service/Daemon, but the scrupt error's when I run it (presumably because it was written for Redhat and not Suse). If anyone can help me I would greatly appreciate it. Here's the error- ln: creating symbolic link `/etc/rc0.d/K98netflowanalyzer' to `/etc/init.d/netflowanalyzer': No such file or directory ln: creating symbolic link `/etc/rc6.d/K98netflowanalyzer' to `/etc/init.d/netflowanalyzer':
High Memory Usage?
I am running NFA 5.0.0 build 5002 on a server (running Linux) that has 2GB of RAM and NFA is using it all. The server when not running NFA is utilizing 25% of memory and after I start NFA it creeps up until it's using 100% (takes about 2 hours to reach 100%). System requirements say 1GB of RAM is enough, do I have a memory leak? Is this normal? Anyone else have this sort of utilization? I am monitoring 33 interfaces.
NFA5 - Srvr Disk (negative on restart)
Hi there, we are running the Trial Version of NFA5 and are already in touch with your team for purchase, Very GUI. compliments. However, i have miscalculated on the Disk reqs. & now the HD is full and the server is not able to restart the NFA service. we are a service org, so have a great need to be able to assess the true reporting and the accuracy, so i would like to retain the data already in the "Data folder". How can i do this, and could you also assist in the determining the true HD reqs? our
Alerts from Netflow
Is it possible to change the e-mail address that alerts come from? Our customers might be confused if they receive an e-mail from netflowreport@localdomain.com. Thank you, Joe
Next Page