<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user">
    <title>gmane.network.flow-tools.user</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1386"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1385"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1384"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1383"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1382"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1381"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1380"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1379"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1378"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1377"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1376"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1375"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1374"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1373"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1372"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1371"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1370"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1369"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1368"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.flow-tools.user/1367"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1386">
    <title>Re: http flow request not displaying flows</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1386</link>
    <description>&lt;pre&gt;flow-tools-bounces-ojNDMRNHqGVygxfI3sfyqtHuzzzSOjJt&amp;lt; at &amp;gt;public.gmane.org wrote on 05/06/2013 04:49:07 PM:


Which web app software are you running? Is it possible the reboot has now
put your server in a different time zone than your devices exporting
netflow? That can cause what you're seeing.

Do a:

flow-print -f5 &amp;lt; ft-v05.2013-05-07.084501+0000 &amp;gt; ~/temp.out

... and compare time-stamps of flows to file creation time.

Joe
&lt;/pre&gt;</description>
    <dc:creator>Joe Loiacono</dc:creator>
    <dc:date>2013-05-07T15:09:34</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1385">
    <title>Re: http flow request not displaying flows</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1385</link>
    <description>&lt;pre&gt;Flow-tools contains a flow collection server and set of command-line utilities, but no web interface. Thus, you must have some other software package providing the web interface (flowscan, flowviewer, webview, or a custom one).

Begin by watching the apache error log (/var/log/apache2/error_log) while you make an http request. The log may provide enough information to fix the problem (e.g., "permission denied").  If it doesn't, it'll at least tell you which script is backfiring and you can figure out where the script came from and how to get support on it. Perhaps it depends on a backend database that failed to start with the reboot.

-Craig


On Mon, 6 May 2013, Kirk Olson wrote:

&lt;/pre&gt;</description>
    <dc:creator>Craig Weinhold</dc:creator>
    <dc:date>2013-05-07T12:29:45</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1384">
    <title>http flow request not displaying flows</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1384</link>
    <description>&lt;pre&gt;In March I rebooted the Ubuntu system running the flow-tools installation.
After the reboot an http request for flow information returns no data
although the apache service seems to be running fine. I can also see flows
being captured in the /var/netflow directory.

I am sure this is more of an Ubuntu admin question so I apologize for my
ignorance. Does anyone have any ideas?

Kirk Olson
_______________________________________________
Flow-tools mailing list
flow-tools-PZzQvgnt7zHEueBKFXcDjA&amp;lt; at &amp;gt;public.gmane.org
http://mailman.splintered.net/mailman/listinfo/flow-tools&lt;/pre&gt;</description>
    <dc:creator>Kirk Olson</dc:creator>
    <dc:date>2013-05-06T20:49:07</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1383">
    <title>Strange ip addresses in flow_capture log files</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1383</link>
    <description>&lt;pre&gt;On my freebsd box:

#uname -rimp
9.1-STABLE amd64 amd64 GENERIC
flow_tools:

Information for flow-tools-0.68_7:


Collector is ng_flow, started with

    /usr/sbin/ngctl mkpeer ipfw: netflow 30 iface0
    /usr/sbin/ngctl name ipfw:30 netflow

    /usr/sbin/ngctl msg netflow: setdlt {iface=0 dlt=12}
    /usr/sbin/ngctl msg netflow: setifindex {iface=0 index=5}
    /usr/sbin/ngctl msg netflow: settimeouts {inactive=15 active=150}
    /usr/sbin/ngctl mkpeer netflow: ksocket export inet/dgram/udp
    /usr/sbin/ngctl msg netflow:export connect inet/127.0.0.1:9995
And ipfw rule:

02750  59239017674  33111253913522 ngtee 30 ip from any to any via em0
Exported with flow_fanout for flow_capture.

# ps axww | grep flow
15106 ??  Ss        2:50,08 /usr/local/bin/flow-fanout -p
/var/run/flow-capture/flow-fanout.pid 127.0.0.1/0.0.0.0/9995
127.0.0.1/127.0.0.1/9556
16367 ??  Ss       11:28,63 /usr/local/bin/flow-capture -n 95 -N 3 -z
5 -S 5 -E270G -w /var/netflow -p
/var/run/flow-capture/flow-capture.pid 127.0.0.1/0.0.0.0/&lt;/pre&gt;</description>
    <dc:creator>Ivan Korjavin</dc:creator>
    <dc:date>2013-03-28T06:51:28</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1382">
    <title>Flowdumper not working after installing Cflow</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1382</link>
    <description>&lt;pre&gt;Hi,

I have installed cflow according to the instructions on the flow-tools 
README file however despite I have several flow files, I am not able to 
get any output at all using the flowdumper program, I have included the full compile process and the actual test so if you can advice me about the possible problem

I have captured the install of Cflow in case you see any errors on the make process

root&amp;lt; at &amp;gt;carlos-VirtualBox:/home/carlos/Downloads/Cflow-1.053# perl Makefile.PL CCFLAGS='-DOSU' LIBS='-lft'
Found flow-tools... using "-DOSU -I../../lib -I../../lib/.. -L../../lib -lft -lz".
Note (probably harmless): No library found for -lft
Writing Makefile for Cflow
Writing MYMETA.yml
root&amp;lt; at &amp;gt;carlos-VirtualBox:/home/carlos/Downloads/Cflow-1.053# locate lft
/etc/bash_completion.d/lftp
/usr/lib/udisks/udisks-helper-ata-smart-selftest
/usr/share/locale-langpack/en_AU/LC_MESSAGES/lftp.mo
/usr/share/locale-langpack/en_GB/LC_MESSAGES/lftp.mo
/usr/share/locale-langpack/zh_CN/LC_MESSAGES/lftp.mo
root&amp;lt; at &amp;gt;carlos-VirtualBox:/home/car&lt;/pre&gt;</description>
    <dc:creator>Carlos Contreras</dc:creator>
    <dc:date>2012-12-12T01:20:58</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1381">
    <title>(no subject)</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1381</link>
    <description>&lt;pre&gt;
http://beautybodystyle.com/blog/wp-content/yepyepop.php       _______________________________________________
Flow-tools mailing list
flow-tools-PZzQvgnt7zHEueBKFXcDjA&amp;lt; at &amp;gt;public.gmane.org
http://mailman.splintered.net/mailman/listinfo/flow-tools&lt;/pre&gt;</description>
    <dc:creator>Amine Mouadden</dc:creator>
    <dc:date>2012-12-04T14:52:09</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1380">
    <title>Good bye, traditional netflow</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1380</link>
    <description>&lt;pre&gt;If you use Cisco products, you may be interested that they've announced the impending end for "traditional netflow" on the ASR1000 line of routers.  Here is the announcement, which includes a link to a whitepaper for migrating traditional to flexible netflow:

  http://www.cisco.com/en/US/prod/collateral/routers/ps9343/eol_C51-718332.html

Traditional netflow is what you have if your interfaces have any of these commands:

 ip route-cache flow
 ip flow ingress
 ip flow egress

The announcement only affects the ASR 1000 series of routers right now, but it points out that newer platforms like the Catalyst 6500/Sup2T, the Catalyst 4500/Sup7E, and the Catalyst 3850 are exclusively supporting flexible netflow. I suspect that the next generation of ISR routers follows suit.

-Craig
&lt;/pre&gt;</description>
    <dc:creator>Craig Weinhold</dc:creator>
    <dc:date>2012-10-26T03:34:15</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1379">
    <title>Re: Netflow v5 pretty much dead what is everyonemigrating to?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1379</link>
    <description>&lt;pre&gt;[..]

effectively:

cflow == NetFlow v5
jflow == NetFlow v9

But due to licensing/naming/tradermarks/patents they are not called that
way.

But we got IPFIX now to solve that part of the hassle.

Greets,
 Jeroen
&lt;/pre&gt;</description>
    <dc:creator>Jeroen Massar</dc:creator>
    <dc:date>2012-10-08T19:24:48</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1378">
    <title>Re: Netflow v5 pretty much dead what is everyonemigratingto?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1378</link>
    <description>&lt;pre&gt;FlowViewer version 4.0 will work with IPFIX/v9 provided you can get a copy 
of SiLK v3.0.

SiLK has been developed by the NetSA group at Carnegie Mellon and it's 
previous versions (prior v3.0) are freely available.

The manager of the SiLK software, Chris Inacio, has told me in emails he 
is getting all of the v3.0 approvals together, but hasn't finalized it.

I believe if you work for a federal agency or are aligned with a US 
research organization (University?) you can get a copy of v3.0 now.

The SiLK software is excellent and worth the wait, but I understand 
network management pressures to move on this.

We've used a free-ware Inmon software tool to convert sflow to netflow v5 
with success.

I've received netflow from Juniper routers and store it with flow-tools 
for years. Is that the same as "jflow"?

Best,

Joe



From:   Drew Weaver &amp;lt;drew.weaver&amp;lt; at &amp;gt;thenap.com&amp;gt;
To:     "flow-tools&amp;lt; at &amp;gt;list.splintered.net" &amp;lt;flow-tools&amp;lt; at &amp;gt;list.splintered.net&amp;gt;
Date:   10/08/2012 12:14 PM
Subject:  &lt;/pre&gt;</description>
    <dc:creator>Joe Loiacono</dc:creator>
    <dc:date>2012-10-08T18:55:34</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1377">
    <title>RE: Netflow v5 pretty much dead what is everyonemigratingto?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1377</link>
    <description>&lt;pre&gt;NFDUMP seems to be alive and up to date but I have not had much time to sit down and actually use it in a significant manner.

http://nfdump.sourceforge.net/




From: flow-tools-bounces-ojNDMRNHqGVygxfI3sfyqtHuzzzSOjJt&amp;lt; at &amp;gt;public.gmane.org [mailto:flow-tools-bounces-ojNDMRNHqGVygxfI3sfyqtHuzzzSOjJt&amp;lt; at &amp;gt;public.gmane.org] On Behalf Of Drew Weaver
Sent: Monday, October 08, 2012 11:14 AM
To: flow-tools-ojNDMRNHqGVygxfI3sfyqtHuzzzSOjJt&amp;lt; at &amp;gt;public.gmane.org
Subject: [Flow-tools] Netflow v5 pretty much dead what is everyone migrating to?

With Netflow v5's life shortening every day what software package are people who are using flow-tools switching to?

It seems like Netflow v9, ipfix, jflow and sflow are all viable technologies; is there a package like flow-tools that has collector and tools that works with all of those?

Thanks,
-Drew
 
If you are not the intended recipient of this message (including attachments) or if you have received this message in error, immediately notify us and delete it as well as any attachments.

&lt;/pre&gt;</description>
    <dc:creator>Volk,Gregory B</dc:creator>
    <dc:date>2012-10-08T16:18:49</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1376">
    <title>Netflow v5 pretty much dead what is everyone migratingto?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1376</link>
    <description>&lt;pre&gt;With Netflow v5's life shortening every day what software package are people who are using flow-tools switching to?

It seems like Netflow v9, ipfix, jflow and sflow are all viable technologies; is there a package like flow-tools that has collector and tools that works with all of those?

Thanks,
-Drew

_______________________________________________
Flow-tools mailing list
flow-tools-PZzQvgnt7zHEueBKFXcDjA&amp;lt; at &amp;gt;public.gmane.org
http://mailman.splintered.net/mailman/listinfo/flow-tools&lt;/pre&gt;</description>
    <dc:creator>Drew Weaver</dc:creator>
    <dc:date>2012-10-08T16:13:35</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1375">
    <title>Re: how get flow fith flow-nfilter for incoming andoutgoing traffic per some net?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1375</link>
    <description>&lt;pre&gt;20.07.2012 16:43, Michael W. Lucas пишет:
Thanks, I found the decision to use "or" design in filter-defination

filter-definition ip-addr
     match ip-destination-address filter-primitive1
     or
     match ip-source-address filter-primitive1

filter-primitive filter-primitive1
     type ip-address-prefix
     permit xx.xx.xx.xx
     default deny


&lt;/pre&gt;</description>
    <dc:creator>Konstantin V. Krotov</dc:creator>
    <dc:date>2012-07-23T11:02:00</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1374">
    <title>Re: how get flow fith flow-nfilter for incoming andoutgoing traffic per some net?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1374</link>
    <description>&lt;pre&gt;Konstantin,

You could also let FlowViewer handle this for you in the user interface. 
You can graph it and track it (via rrdtool) as well.

http://ensight.eos.nasa.gov/FlowViewer/

Joe Loiacono




From:   "Konstantin V. Krotov" &amp;lt;kkv-SNifSdt4gYYox3rIn2DAYQ&amp;lt; at &amp;gt;public.gmane.org&amp;gt;
To:     flow-tools-ojNDMRNHqGVygxfI3sfyqtHuzzzSOjJt&amp;lt; at &amp;gt;public.gmane.org
Date:   07/20/2012 07:09 AM
Subject:        [Flow-tools] how get flow fith flow-nfilter for incoming 
and outgoing traffic per some net?
Sent by:        flow-tools-bounces-ojNDMRNHqGVygxfI3sfyqtHuzzzSOjJt&amp;lt; at &amp;gt;public.gmane.org



hello, list!
Plese, give:
how get flow fith flow-nfilter for incoming and outgoing traffic per 
some net for one request?
like nfdump tool:
nfdump 'ip xx.xx.xx.xx'?

&lt;/pre&gt;</description>
    <dc:creator>Joe Loiacono</dc:creator>
    <dc:date>2012-07-20T13:30:30</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1373">
    <title>Re: how get flow fith flow-nfilter for incoming andoutgoing traffic per some net?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1373</link>
    <description>&lt;pre&gt;
Write a custom report. I put an example in:

http://blather.michaelwlucas.com/archives/494

You can also do a custom report that takes an IP address variable on
the command line.

==ml

On Fri, Jul 20, 2012 at 03:08:46PM +0400, Konstantin V. Krotov wrote:

&lt;/pre&gt;</description>
    <dc:creator>Michael W. Lucas</dc:creator>
    <dc:date>2012-07-20T12:43:08</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1372">
    <title>how get flow fith flow-nfilter for incoming and outgoing traffic per some net?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1372</link>
    <description>&lt;pre&gt;hello, list!
Plese, give:
how get flow fith flow-nfilter for incoming and outgoing traffic per 
some net for one request?
like nfdump tool:
nfdump 'ip xx.xx.xx.xx'?

&lt;/pre&gt;</description>
    <dc:creator>Konstantin V. Krotov</dc:creator>
    <dc:date>2012-07-20T11:08:46</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1371">
    <title>Re: Where did the community go?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1371</link>
    <description>&lt;pre&gt;Would be great if there was an intermediate daemon that could grab v9/ipfix and convert it to v5 at least for now :)

Craig Weinhold &amp;lt;craig.weinhold-22trykYRFPg&amp;lt; at &amp;gt;public.gmane.org&amp;gt; wrote:


Netflow v9 / IPFIX is not going to be added to flow-tools without a near-complete rewrite.

The problem with the v5 paradigm is that everything is built around fixed length records with 7-tuple keys (src/dst ip, src/dst port, protocol, tos, and input interface) and simple data fields (bytes, packets, start time, end time, etc).  Unfortunately, silk, flowd, and (I think) nfdump all continue with this paradigm. They may have added IPv6, but they basically toss out other v9/IPFIX fields. You see, V9 is open-ended with both its keys and its data fields. Think RADIUS vendor-supported attributes. The record length of each flow is not fixed, and the interpretation of flow data changes dramatically from device-to-device and config-to-config.

For example, Cisco ASA firewalls use Netflow v9 for logging both blocked and allowed traff&lt;/pre&gt;</description>
    <dc:creator>Drew Weaver</dc:creator>
    <dc:date>2012-04-12T18:28:16</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1370">
    <title>Re: Where did the community go?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1370</link>
    <description>&lt;pre&gt;  Hi Craig,

  I believe nprobe running as collector should do all this through
Netflow v9 templates

  Is the one we will use for our project

Jaime Nebrera
Enviado / Sent iPhone

El 12/04/2012, a las 18:58, Craig Weinhold &amp;lt;craig.weinhold-22trykYRFPg&amp;lt; at &amp;gt;public.gmane.org&amp;gt; escribió:

&lt;/pre&gt;</description>
    <dc:creator>Jaime Nebrera</dc:creator>
    <dc:date>2012-04-12T17:56:42</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1369">
    <title>Re: Where did the community go?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1369</link>
    <description>&lt;pre&gt;  Hi Michael,

Jaime Nebrera
Enviado / Sent iPhone


  We can't make any code available just yet as we dint start the development :)

  Let me explain a bit:

  By end of month we will release to public the open source framework
we have done to manage snort deployments (RoR based)

  After that we will start a new project, a replacement of our current
netflow collector (java + flowtools based)

  What we would like to achieve is to get a group of funders for such
development as well as developers, designers, community interested in
participating. The project will be done even without funders but of
course would be easier if we have them :D

  The backend would be nprobe (www.ntop.org) based. Sadly this great
software has two weak points: lack of a proper web interface and
support fir the wrong nosql technology (fastbit)

  Thus the project would be about adding support to some other noSQL
engine on nprobe (hbase, Cassandra, hypertable we don't know yet) and

  To develop a new modern web based interface for &lt;/pre&gt;</description>
    <dc:creator>Jaime Nebrera</dc:creator>
    <dc:date>2012-04-12T17:54:32</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1368">
    <title>Re: Where did the community go?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1368</link>
    <description>&lt;pre&gt;Netflow v9 / IPFIX is not going to be added to flow-tools without a near-complete rewrite.

The problem with the v5 paradigm is that everything is built around fixed length records with 7-tuple keys (src/dst ip, src/dst port, protocol, tos, and input interface) and simple data fields (bytes, packets, start time, end time, etc).  Unfortunately, silk, flowd, and (I think) nfdump all continue with this paradigm. They may have added IPv6, but they basically toss out other v9/IPFIX fields. You see, V9 is open-ended with both its keys and its data fields. Think RADIUS vendor-supported attributes. The record length of each flow is not fixed, and the interpretation of flow data changes dramatically from device-to-device and config-to-config.

For example, Cisco ASA firewalls use Netflow v9 for logging both blocked and allowed traffic, but you need to be able to see the extra fields to determine which. I think nfdump has some hacks to handle this.

Or, consider a router sending duplicate flows (e.g., "ip flow ingress&lt;/pre&gt;</description>
    <dc:creator>Craig Weinhold</dc:creator>
    <dc:date>2012-04-12T16:58:44</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1367">
    <title>Re: Where did the community go?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1367</link>
    <description>&lt;pre&gt;
Hi,

Yes, I saw it, but it's hard to comment without the actual code. :-)

You should send an announcement when you have something we can
install.

Thanks,
==ml

&lt;/pre&gt;</description>
    <dc:creator>Michael W. Lucas</dc:creator>
    <dc:date>2012-04-12T16:15:55</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.flow-tools.user/1366">
    <title>Re: Where did the community go?</title>
    <link>http://permalink.gmane.org/gmane.network.flow-tools.user/1366</link>
    <description>&lt;pre&gt;   Hi Michael,


   We are about to start such project very soon.

   I dont know if my first email went through to the list but the idea 
would be to:

   * Netflow v5, v9, sFlow and IPFIX compatibility
   * noSQL backend (provably Hypertable based)
   * Web front end (RoR)
   * For sure, all open source

   For sure, all open sourced and even supported commercially. This 
project will go along the first one done for Snort that will be released 
to public April 24th (more or less)

&lt;/pre&gt;</description>
    <dc:creator>Jaime Nebrera</dc:creator>
    <dc:date>2012-04-12T15:42:49</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.network.flow-tools.user">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.network.flow-tools.user</link>
  </textinput>
</rdf:RDF>
