pmacct
by Paolo Lucente
Platforms: FreeBSD, IRIX, Linux, NetBSD, OpenBSD, Solaris, True64 UNIX
Categories: Monitoring, Network Monitoring, Network Utilities
Version: 0.9.3
URL: http://www.ba.cnr.it/~paolo/pmacct/
pmacct is a small set of passive network monitoring tools to measure, account and

aggregate IPv4 and IPv6 traffic; aggregation revolves around the key concept of

primitives (VLAN id, source and destination MAC addresses, hosts, networks, ports,

AS numbers, IP protocol and ToS/DSCP field are supported) which may be arbitrarily

combined to build custom aggregation methods; support for historical data breakdown,

triggers and packet tagging, filtering, sampling. Aggregates can be stored into

memory tables, SQL databases (MySQL or PostgreSQL) or simply pushed to stdout. Data

is collected from the network either using libpcap (and optionally promiscuous mode)

or reading Netflow v1/v5/v7/v8/v9 and sFlow v2/v4/v5 datagrams.

Privacy Statement
Copyright 2006, SecurityFocus