Wed Oct 27, 2010 4:02 pm
Yes. We do it the following way:
- We've set up IP / Packet flow v5 on the routers and we send the flows to a linux monitoring server
- There we pick up the flows with a flow collector and send them to 2 temporary local streams (pmacct/nfacct)
- The local streams get incremented with the bytes per IP as the flows come in
- We then process the collected information using cacti and pmacct plugin, we turn bytes/time interval to bits per second and reset the counters in the temporary local streams. We average on the traffic made. We use 1 minute pooling without spine and it works perfect. With spine it will get a little tricky.