Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

The OSU Flow-tools Package and CISCO NetFlow Logs

Many Cisco routers and switches support NetFlow services which provides a detailed source of data about network traffic. The Office of Information Technology Enterprise Networking Services group (OIT/ENS) at The Ohio State University (OSU) has written a suite of tools called flow-tools to record, filter, print and analyze flow logs derived from exports of NetFlow accounting records. We use the flow logs for general network planning, performance monitoring, usage based billing, and many security related tasks including incident response and intrusion detection. This paper describes what the flow logs contain, the tools we have written to store and process these logs, and discusses how we have used the logs and the tools to perform network management and security functions at OSU. We also discuss some related projects and our future plans at the end of the paper.

Mark Fullmer, OARnet

Steve Romig, The Ohio State University

BibTeX
@inproceedings {271109,
author = {Mark Fullmer and Steve Romig},
title = {The {OSU} Flow-tools Package and {CISCO} {NetFlow} Logs},
booktitle = {14th Systems Administration Conference (LISA 2000)},
year = {2000},
address = {New Orleans, LA},
url = {https://www.usenix.org/conference/lisa-2000/osu-flow-tools-package-and-cisco-netflow-logs},
publisher = {USENIX Association},
month = dec
}
Download

Links

Paper: 
http://www.usenix.org/events/lisa2000/full_papers/fullmer/fullmer.pdf
Paper (HTML): 
http://www.usenix.org/events/lisa2000/full_papers/fullmer/fullmer_html/index.html
  • Log in or register to post comments

© USENIX
EIN 13-3055038

LISA is a registered trademark of the USENIX Association.

  • Privacy Policy
  • Contact Us