Recommended Posts

Are there any good free / not ultra expensive monitor systems out there that can parse netflow data from a cisco ASA box? I'm just looking for something to tell me what IP's are using bandwidth and log some basic info on them like how much they used, etc.... I ran across NTop but it didn't seem to like to work right for me in windows. what else is out there?

Link to comment
https://www.neowin.net/forum/topic/1317380-netflow-logger-monitoring/
Share on other sites

Take a look at

https://www.manageengine.com/products/netflow/

 

what ntop were you looking at, the old ntop or ntopng ?  Running on windows clunky..

 

Prtg has some netflow suppport.  Here is another free one to get started with

https://www.plixer.com/products/scrutinizer/free-edition/

 

How many devices are you talking , now many flows?  Sounds like your just looking for top talkers?

  On 26/12/2016 at 14:08, BudMan said:

Take a look at

https://www.manageengine.com/products/netflow/

 

what ntop were you looking at, the old ntop or ntopng ?  Running on windows clunky..

 

Prtg has some netflow suppport.  Here is another free one to get started with

https://www.plixer.com/products/scrutinizer/free-edition/

 

How many devices are you talking , now many flows?  Sounds like your just looking for top talkers?

Expand  

ntopng was the one I was playing with, and yes it was very clunky

 

and one device, still on the learning what I can about cisco track...

 

trying to get an idea of who is using what (bandwidth wise) over time, and who at this specific point in time is using what if its possible to get that

ntopng for sure could show you that.. You were trying to run it on windows? How did you setup the flows, you need to setup a virtual interface, etc.  Where did you connect it? etc..

 

Check out the manage engine.. Its free for 2 interfaces sending flows I believe.

https://www.manageengine.com/products/netflow/download-free.html

 

Prob going to be simpler setup out of the gate..

 

if you don't want to mess with flows the real simple way to do it to use some cheap smart switch as a tap, if your switches does not allow for it, etc.  And then connect your box running ntop to the span port and you will get all your info you wanted without having to setup any flows.

 

ntop.png

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.