<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sflow for monitoring in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/sflow-for-monitoring/m-p/46047#M11594</link>
    <description>Hi, &lt;BR /&gt;
&lt;BR /&gt;
I'm trying to collect sflow from a BD8800 to use it in a ELK stack.&lt;BR /&gt;
I'm actually able to receive the sflow data, now i have to parse it to be able to make some search/ analyse on it.&lt;BR /&gt;
Did anyone know the mapping of sflow data .&lt;BR /&gt;
&lt;BR /&gt;
Actually i receive somthing like this :&lt;BR /&gt;
&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;u0000\u0000\u0000\u0005\u0000\u0000\u0000\u0001\xAC\u0010\u0000\u0001\u0000\u0000\u0000\u0000\u0000\u0002'\xD3\u0004\u001F\x92H\u0000\u0000\u0000\v\u0000\u0000\u0000\u0002\u0000\u0000\u0000l\u0000\u0000gi\u0000\u0000\u0003\xF2\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0001\u0000\u0000\u0000X\u0000\u0000\u0003\xF2\u0000\u0000\u0000\a\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002\u0000\u0000\u0000\u0002\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u000&lt;/BLOCKQUOTE&gt;</description>
    <pubDate>Thu, 19 May 2016 20:17:00 GMT</pubDate>
    <dc:creator>Trasschaert_Kar</dc:creator>
    <dc:date>2016-05-19T20:17:00Z</dc:date>
    <item>
      <title>Sflow for monitoring</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/sflow-for-monitoring/m-p/46047#M11594</link>
      <description>Hi, &lt;BR /&gt;
&lt;BR /&gt;
I'm trying to collect sflow from a BD8800 to use it in a ELK stack.&lt;BR /&gt;
I'm actually able to receive the sflow data, now i have to parse it to be able to make some search/ analyse on it.&lt;BR /&gt;
Did anyone know the mapping of sflow data .&lt;BR /&gt;
&lt;BR /&gt;
Actually i receive somthing like this :&lt;BR /&gt;
&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;u0000\u0000\u0000\u0005\u0000\u0000\u0000\u0001\xAC\u0010\u0000\u0001\u0000\u0000\u0000\u0000\u0000\u0002'\xD3\u0004\u001F\x92H\u0000\u0000\u0000\v\u0000\u0000\u0000\u0002\u0000\u0000\u0000l\u0000\u0000gi\u0000\u0000\u0003\xF2\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0001\u0000\u0000\u0000X\u0000\u0000\u0003\xF2\u0000\u0000\u0000\a\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002\u0000\u0000\u0000\u0002\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u000&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Thu, 19 May 2016 20:17:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/sflow-for-monitoring/m-p/46047#M11594</guid>
      <dc:creator>Trasschaert_Kar</dc:creator>
      <dc:date>2016-05-19T20:17:00Z</dc:date>
    </item>
    <item>
      <title>RE: Sflow for monitoring</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/sflow-for-monitoring/m-p/46048#M11595</link>
      <description>I don't understand you mean by "mapping of sflow data", please elaborate. EXOS conforms to the sflow standard defined in RFC 3176 particularly, version 5 which I believe is an improvement over the original FRC.  The particular packet structure is defined in the following document: &lt;A href="http://www.sflow.org/SFLOW-DATAGRAM5.txt" target="_blank" rel="nofollow noreferrer noopener"&gt;http://www.sflow.org/SFLOW-DATAGRAM5.txt&lt;/A&gt;&lt;B&gt;.  &lt;/B&gt;If you take a packet capture of the traffic an EXOS device is sending to the collector, below is what you should see when you expand the sFlow section:&lt;BR /&gt;
InMon sFlow     Datagram version: 5     Agent address type: IPv4 (1)     Agent address: &lt;SWITCH-IP&gt;     Sub-agent ID: 0     Sequence number: 755859     SysUptime: 1919217650     NumSamples: 11          Counters sample, seq 141485         0000 0000 0000 0000 0000 .... .... .... = Enterprise: standard sFlow (0)         .... .... .... .... .... 0000 0000 0010 = sFlow sample type: Counters sample (2)         Sample length (byte): 108         Sequence number: 141485         0000 0000 .... .... .... .... .... .... = Source ID type: 0         .... .... 0000 0000 0000 0011 1110 1011 = Source ID index: 1003         Counters records: 1         Generic interface counters             0000 0000 0000 0000 0000 .... .... .... = Enterprise: standard sFlow (0)             .... .... .... .... .... 0000 0000 0001 = Format: Generic interface counters (1)             Flow data length (byte): 88             Interface index: 1003             Interface Type: 7             Interface Speed: 1000000000             Interface Direction: Full-Duplex (1)             .... .... .... .... .... .... .... ...1 = IfAdminStatus: Up             .... .... .... .... .... .... .... ..1. = IfOperStatus: Up             Input Octets: 16893026             Input Packets: 24396             Input Multicast Packets: 122631             Input Broadcast Packets: 0             Input Discarded Packets: 0             Input Errors: 0             Input Unknown Protocol Packets: 0             Output Octets: 23915928             Output Packets: 24841             Output Multicast Packets: 41351             Output Broadcast Packets: 172509             Output Discarded Packets: 0             Output Errors: 0             Promiscuous Mode: 1 Is this what you're asking about?&lt;/SWITCH-IP&gt;</description>
      <pubDate>Wed, 01 Jun 2016 18:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/sflow-for-monitoring/m-p/46048#M11595</guid>
      <dc:creator>Kawawa</dc:creator>
      <dc:date>2016-06-01T18:43:00Z</dc:date>
    </item>
    <item>
      <title>RE: Sflow for monitoring</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/sflow-for-monitoring/m-p/46049#M11596</link>
      <description>looks like you are trying to parse the sflow data yourself and not use a sflow analytic software?  There are many software options for turning sflow collected packets into usable data and analysis.   We use Solarwinds and have about 3500 interfaces we are getting flow data from.</description>
      <pubDate>Wed, 01 Jun 2016 19:03:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/sflow-for-monitoring/m-p/46049#M11596</guid>
      <dc:creator>EtherMAN</dc:creator>
      <dc:date>2016-06-01T19:03:00Z</dc:date>
    </item>
  </channel>
</rss>

