On Mon, Apr 08, 2002 at 10:08:32AM -0700, Annie Tong wrote: > I'm wondering does ethereal read the captured netflow data from Cisco? >From a quick look at http://www.cisco.com/warp/public/cc/pd/iosw/prodlit/tflow_wp.htm it appears that NetFlow data contains statistical information about traffic flow, rather than raw packets, so: > Ethereal > seems to be an interesting and useful tool and I would like to use it as > the traffic analyser if it's compatiable to Flow-Tool formatted raw data. ...it's not clear that Ethereal, which is a network analyzer for looking at raw traffic, rather than a tool for viewing summary statistics (even the summary statistics it displays are produced by processing raw traffic captures), would be able to do anything with NetFlow data. Ntop, as per the other reply, may be a better choice, as that's a tool for network statistics.
Powered by MHonArc 2.6.10