Xenoeye Netflow Collector Released

The Xenoeye Netflow Collector is now available, enabling the collection of traffic flow statistics from various network devices using Netflow v9 and IPFIX protocols, processing data, generating reports, and creating graphs. Additionally, the collector can run custom scripts when thresholds are exceeded. The project core is written in C, and the code is distributed under the ISC license.

Collector Features:

  • Aggregated data by the necessary Netflow fields is exported to PostgreSQL. Preliminary aggregation occurs within the collector.
  • Only a basic set of Netflow fields is supported out of the box, but almost any field can be added.
  • The collector's performance can reach several hundred thousand 'flows per second' on a single CPU, depending on the nature of the traffic and reports. The load distribution model is per device (router) per flow.
  • The collector uses moving averages to calculate traffic speed exceedances.
  • The collector can be used to identify infected hosts (sending email spam, HTTP(S) floods, SSH scanners) and detect sharp spikes during DoS/DDoS attacks.
  • Network reports can be visualized using various utilities: gnuplot, Python scripts + Matplotlib, or Grafana.
  • Unlike many modern collectors, this project does not use Apache Kafka, Elastic, etc.; most calculations are performed within the collector itself.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster