/etc/octopussy/conf/services/NetFlow.xml is in octopussy 1.0.6-0ubuntu2.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 | <?xml version='1.0' encoding='UTF-8'?>
<octopussy_service description="NetFlow Network Protocol"
name="NetFlow"
nb_messages="002"
version="201109150002"
website="http://en.wikipedia.org/wiki/Netflow">
<message loglevel="Information"
msg_id="NetFlow:flow_capture_stat"
pattern="<@DATE_TIME_ISO:datetime@> <@WORD:device@> flow-capture[<@PID:pid@>]: STAT: now=<@SECONDS:now@> startup=<@SECONDS:startup@> src_ip=<@IP_ADDR:src_addr@> dst_ip=<@IP_ADDR:dst_addr@> d_ver=<@NUMBER:d_version@> pkts=<@NUMBER:pkts@> flows=<@NUMBER:flows@> lost=<@NUMBER:lost@> reset=<@NUMBER:reset@> filter_drops=<@NUMBER:filter_drops@>"
rank="001"
table="NetFlow_Traffic"
taxonomy="Network" />
<message loglevel="Notice"
msg_id="NetFlow:flow_capture_stat_ftpdu_seq_check"
pattern="<@DATE_TIME_ISO:datetime@> <@WORD:device@> flow-capture[<@PID:pid@>]: ftpdu_seq_check(): src_ip=<@IP_ADDR:src_addr@> dst_ip=<@IP_ADDR:dst_addr@> d_version=<@NUMBER:d_version@> expecting=<@NUMBER:expecting@> received=<@NUMBER:received@> lost=<@NUMBER:lost@>"
rank="002"
table="NetFlow_Traffic"
taxonomy="Network" />
</octopussy_service>
|