Packet Flow Data 24.03 in comparison to softflowd
-
Just want to share my findings when comparing softflowd with the new feature Packet Flow Data in 24.03.
When using softflowd, if the traffic was huge, let's say around 1Gbps, softfowd would get up to 4 or 5% of CPU usage.
Now, with this Packet Flow Data in 24.03, there is no impact what so ever in my CPU.
So, from now on, Packet Flow Data is the way for me now.
Thanks Netgate team, really liked this
-
@mcury Not only that, but the granularity is FABULOUS! because you can decide on a per rule basis on which flows to collect. That removes a LOT of useless logging and clutter in my flow analyzer :-)
Also: It doesn't seem to occasionally break flows into several smaller flows like SoftflowD did.
-
@keyser said in Packet Flow Data 24.03 in comparison to softflowd:
@mcury Not only that, but the granularity is FABULOUS! because you can decide on a per rule basis on which flows to collect. That removes a LOT of useless logging and clutter in my flow analyzer :-)
Good point there, I didn't have time to play with the per rule basis yet, but I'll will soon :)
Also: It doesn't seem to occasionally break flows into several smaller flows like SoftflowD did.
I'm still testing, so far, so much better than SoftflowD.
But I can't speak badly about SoftflowD because for a long time, it was the only option and served me pretty well. So thanks for the developer and everyone involved in that project.
-
@mcury If I may ask, what are you using for collecting/storage/display of flows?
-
@dennypage said in Packet Flow Data 24.03 in comparison to softflowd:
@mcury If I may ask, what are you using for collecting/storage/display of flows?
Hello dennypage,
I'm using Graylog server community edition with opensearch (updated from elasticsearch a few months ago). -
@mcury said in Packet Flow Data 24.03 in comparison to softflowd:
But I can't speak badly about SoftflowD because for a long time, it was the only option and served me pretty well. So thanks for the developer and everyone involved in that project.
Niether can I, worked great for me these years.
One note though, there might be an issue when pfflow is only based on expiring States. That could mean keepalive sessions are never logged as flows