Nfdump 1.6.12

Set of tools to collect and process netflow data
Nfdump is a set of tools to collect and process netflow data. It's fast and has a powerful filter pcap like syntax.

Nfdump supports netflow versions v5, v7 and v9 as well as a limited set of sflow and is IPv6 compatible.

The nfdump tools process and collect netflow data on the command line.

Nfdump contains the following tools:

nfcapd - netflow capture daemon.
·Reads the netflow data from the network and stores the data into files. Automatically rotate files every n minutes. ( typically ever 5 min ) nfcapd reads netflow v5, v7 and v9 flows transparently. You need one nfcapd process for each netflow stream.

nfdump - netflow dump.
·Reads the netflow data from the files stored by nfcapd. It's syntax is similar to tcpdump. If you like tcpdump you will like nfdump. Displays netflow data and can create lots of top N statistics of flows IP addresses, ports etc ordered by whatever order you like.

nfprofile - netflow profiler.
·Reads the netflow data from the files stored by nfcapd. Filters the netflow data according to the specified filter sets ( profiles ) and stores the filtered data into files for later use.

nfreplay - netflow replay
·Reads the netflow data from the files stored by nfcapd and sends it over the network to another host. - cleanup old data
·Sample script to cleanup old data. You may run this script every hour or so.

ft2nfdump - Read and convert flow-tools data.
·Reads flow-tools data from files or from stdin in a chain of flow-tools commands and converts the data into nfdump format to be processed by nfdump.

last updated on:
April 14th, 2014, 3:04 GMT
file size:
732 KB
developed by:
Peter Haag
license type:
operating system(s):
Mac OS X
binary format:
Universal Binary
Home \ Network/Admin


In a hurry? Add it to your Download Basket!

user rating 20



Rate it!
1 Screenshot
Nfdump - Usage screen for the application when running it from a Terminal window.
What's New in This Release:
  • Add NAT pool port allocation
  • Modify/fix NAT vrf tags. Add egress vrf ID
  • Modify common record due to exporter exhaustion. new common record type 10 adds 4 extra bytes. Reads v1 common record transparently
  • Fix sflow potential crash
read full changelog

Add your review!