Nfsen-netflow Sensor
Nfsen is a WEB front end that graphically displays nfdump netflow tools data.
Nfsen can:
1. Display netflow data: display streams, packets and bytes using rrd
2. Browse netflow data easily
3. Analyze and process netflow data based on a specific time range
4. Generate historical data archives
5. Setting alarms based on multiple conditions
6. Write plug-ins to process netflow data at regular intervals
Different tasks need to be based on different interfaces for processing netflow data. Nfsen allows you to keep processing netflow data directly from the nfdump command line with great advantage, while giving a graphical presentation.
Nfsen is available through http://sourceforge.net/projects/nfsen/, and all versions support BSD licensing.
Version:
Stable version: 1.3.6 and nfdump 1.6.5 (released on December 31, 2011)
Snapshot: may provide stable releases and distributions similar to snapshot-yyyymmdd
This document refers to version 1.3.2.
Note: all IP appearing in this document is fictional, and it is a pure coincidence that there are any similarities.
NFSEN installation:
PHP and Perl:
Nfsen is written in php and Perl languages and can run on all Linux-like systems
A minimum of Perl 5.6.0 and PHP > 4.1 are required, including the necessary socket and Perl extension support for regular expressions.
Perl module:
The nfsen alarm function requires the Perl module of Mail::header,Mail::Internet
RRD tool:
Nfsen uses rrd for drawing, and at least needs to support rrds Perl Module
Nfdump tool
Nfdump is a back-end tool for nfsen and uses it to collect and process netflow data. You need to make sure that the installation version is > 1.5.8, and do not install a version lower than 1.5.5. You can download http://nfdump.sourceforge.net/ from sourcefore
Installation of nfsen: