The release of the Netflow/IPFIX collector Xenoeye 23.11.

The release of the Netflow/IPFIX collector Xenoeye 23.11 has been published. It allows for the collection of traffic flow statistics from various network devices transmitted using Netflow v5, v9, and IPFIX protocols. Additionally, it can process data, generate reports, and create graphs. The project's core is written in C, and the code is distributed under the ISC license.

The collector aggregates network traffic based on selected fields and exports the data to PostgreSQL. Reports, graphs (using gnuplot, Python scripts + Matplotlib), or dashboards in Grafana can be created with this data. Furthermore, the collector can run custom scripts when thresholds are exceeded. A moving average is used to calculate traffic speed. Included with the collector is an example script for a Telegram bot that can notify the messenger when speeds exceed certain thresholds.

The release of the Netflow/IPFIX collector Xenoeye 23.11.

Changes in the new version:

  • The ability to use GeoIP with ipapi databases has been added. By utilizing GeoIP functions, monitoring geo-objects can be created (for example, to isolate all traffic from Russia into a separate monitoring object) and export data broken down by GeoIP. The collector supports detailing by countries, regions, and cities. Additionally, longitude and latitude can be obtained from an IP address (though it's important to note that this can be quite approximate).
  • For routers that cannot export autonomous system numbers in Netflow/IPFIX, there is an option to obtain these numbers and their textual descriptions using ip-location-db. Just like with GeoIP, separate monitoring objects can be created that include traffic from selected AS or export the names of autonomous systems to a database.
  • Traffic classification by netflow fields has been added. The collector can classify monitoring objects using certain fields (TCP flags, ports, packet sizes).
  • A console utility, xegeoq, has been added, which allows you to obtain GeoIP information and AS information from IP addresses using local databases.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster