
Trying to understand nfdump output

as flag

I am trying to figure out meaning in a nfdump output, but I cannot seem to find any sources for this. For now I am mostly trying to understand what some of the categories mean.

What I have is a basic output with the following fields: Date first seen Event XEvent Proto Src IP Addr:Port Dst IP Addr:Port X-Src IP Addr:Port X-Dst IP Addr:Port In Byte Out Byte

In all entries of the output the "Event" is "INVALID", "Xevent" is "Ignore", "X-Src" and "X-Dst" are "". So what exactly are these fields telling me? What do they mean?

Is there a list of possible fields and there meaning? Because me doing Google doesn't help much.

Nikita Kipriyanov avatar
za flag
Haven't you just missed the first place to look at, [man nfdump](
arnby avatar
as flag
Well, yes and no. I did not take a good look, but it doesn’t help much when I do. It moves the question to NSEL/ASA stats which is just as obscure. Like event is NSEL/ASA event and xevent is NSEL/ASA extended event
Nikita Kipriyanov avatar
za flag
No, because it would hint at Cisco ASA NetFlow Secure Event Logging. Which could imply that these fields are meaningful only for flows collected from ASA device.
I sit in a Tesla and translated this thread with Ai:


Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.