5. 徭恬Netflowコレクタ
5
flow record FLOW-RECORD
match ipv4 protocol
match ipv4 source address
match ipv4 destination address
match transport source-port
match transport destination-port
match application name
collect counter bytes
collect counter packets
collect timestamp absolute first
collect timestamp absolute last
テンプレ`トフロ`セットから
デ`タフロ`セットを啜弔暴睥し、
m俳なフィ`ルド兆になる
https://github.com/tetsusat/fnfc
ル`タのO協
10. ? アプリケ`ション阿離丱ぅ畔
Apache Spark + Apache Zeppelin 3/6
%sql
SELECT record.application_name, sum(record.client_bytes) bytes FROM records GROUP BY record.application_name
11. ? アプリケ`ション阿離丱ぅ畔WHERE鞘をパラメ`タ晒
Apache Spark + Apache Zeppelin 4/6
%sql
SELECT record.application_name, sum(record.client_bytes) bytes FROM records
WHERE record.ipv4_src_addr="${src}" AND record.ipv4_dst_addr="${dst}"
GROUP BY record.application_name
14. ? 蒙協の1晩で30蛍阿離丱ぅ畔を鹿
Apache Spark + Apache Zeppelin 5/6
%sql
SELECT from_unixtime(m.timeslot*(30*60)) dtime, sum(m.bytes) bytes
FROM (
SELECT record.client_bytes bytes, floor(unix_timestamp(record.absolute_first)/(30*60)) timeslot
FROM records
WHERE record.absolute_first >= "2016-03-24" AND record.absolute_first < "2016-03-25^
) AS m
GROUP BY m.timeslot ORDER BY m.timeslot
16. ? 蒙協の1晩で30蛍阿離丱ぅ畔を鹿┘▲廛螢羽`ション阿亮s
Apache Spark + Apache Zeppelin 6/6
%sql
SELECT from_unixtime(m.timeslot*(30*60)) dtime, m.app, sum(m.bytes) bytes
FROM (
SELECT record.client_bytes bytes, record.application_name app, floor(unix_timestamp(record.absolute_first)/(30*60)) timeslot
FROM records
WHERE record.absolute_first >= "2016-03-24" AND record.absolute_first < "2016-03-25^
) AS m
GROUP BY m.timeslot, m.app ORDER BY m.timeslot