Wednesday, January 31, 2018

IPFIX collector?

Hey all,

I am looking for an open source IPFIX collector with decent documentation. I looked at ELK with the netflow codec, but it doesn't look like IPFIX is quite there yet with Juniper gears, and I'm really not trying to spend a month forcing this to do what I want it to do.

I also rolled across vflow but the documentation is sparse to say the least. The idea that I'd have to roll out zookeeper/kafka/InfluxDB along with vflow, figure out how to get them all talking in a meaningful way (sans documentation of any sort on the vflow side), then work out something for dashboards seems like a bit much.

The budget I was given for a paid solution was 2k for the year... and that seems a bit unrealistic after looking around some.

Anybody got a suggestion that works decently without all the headache? I have a decent bit on my plate, and I'd rather not have to dedicate too much time to something that should be so simple. v9 flows aren't an option for me unfortunately, or this would be done in a day.

If I have to invest all the time, then I guess I have to do that - just seeing what's out here and reliable first before I begin the trench digging.

Thanks!



No comments:

Post a Comment