Scrutinizer Linux Version

Scrutinizer is an enterprise/business class NetFlow and sFlow analysis tool. Scrutinizer provides historical trends of the company's critical network interfaces as well as the details on:

Who: The end system causing the traffic
What: The application/protocol that is being used
When: The time frame it has been occurring for
Where: The network connection that is affected

Moderators: scottr, Moderator Team

Scrutinizer Linux Version

Postby tonydahle » Wed Feb 03, 2010 12:48 pm

Currently we are using the 6.0.marc version of scrutinizer on a Linux VM.

What I would like to know is if there are any plans to port Version 7 to Linux.

I want to avoid the nasty overhead associated with running a Windows server. Here is what I can save by having a Linux version:
1. I can easily save at least a gig of memory by running it in Linux. - I need an Antivirus, Active Directory connections, and Software updaters on a Windows Box in our company
2. Time - Uptime is important in monitoring tools. Having a Windows installation means reboot after reboot whenever any program needs an update.
3. Cost / Scale - Running scrutinizer in a VM works great for us. If we switch to the windows version we would need to go to a bare iron install.

Please let me know if this is in the works.

Thanks,
Tony
tonydahle
 
Posts: 4
Joined: Wed Feb 03, 2010 12:18 pm

Re: Scrutinizer Linux Version

Postby tomp » Wed Feb 03, 2010 1:44 pm

I regret to inform you that we have decided not to pursue a Scrutinizer 7 Linux build at this time. There is currently no time line of a release.

I apologize for any inconvenience this may cause you.

How many exporting devices is Scrutinizer collecting from?

- Tom
User avatar
tomp
Site Admin
 
Posts: 289
Joined: Wed Jul 27, 2005 9:53 am
Location: Sunny Sanford Maine

Re: Scrutinizer Linux Version

Postby tonydahle » Wed Feb 03, 2010 3:34 pm

Not that many:

Cisco:
36 - 1800 series / 881w - SOHO Routers - all through VPN tunnels
4 - 2800 series - Remote Office Routers - all through VPN tunnels
1 - 3800 series - MPLS Head
10 - 5500 series ASA's - Firewalls / VPN Heads
a few switches

I want to set up a few nprobes around our network, but I am having a hard time figuring out the right syntax for a Windows nprobe. (all the documentation I can find is for linux nprobes)

Tony
tonydahle
 
Posts: 4
Joined: Wed Feb 03, 2010 12:18 pm

Re: Scrutinizer Linux Version

Postby tonydahle » Tue Feb 09, 2010 2:23 pm

I installed Version 7.5.1 on a Windows 7 box and I can not get Netflow V9 flows from nProbe, but I can get the information clearly on my v6 Virtual appliance.

The nProbe is running on another Win7 box and is using the following string (IPs changed):

nprobe /i nprobe -n 172.16.2.2:2055 -n 172.16.3.3:2055 -i 0 -i 1 -u 1 -Q 1 -l 5 -t 5 -d 5 -s 5 -V 9 -T "%IPV4_SRC_ADDR %IPV4_DST_ADDR %IPV4_NEXT_HOP %INPUT_SNMP %OUTPUT_SNMP %OUT_PKTS %OUT_BYTES %FIRST_SWITCHED %LAST_SWITCHED %L4_SRC_PORT %L4_DST_PORT %TCP_FLAGS %PROTOCOL %SRC_TOS %SRC_AS %DST_AS %SRC_MASK %DST_MASK"

The 172.16.2.2 is our old v6 Virtual Appliance and the 172.16.3.3 is the v7 box.

Looks like I am sticking with my current 6.0 Linux Virtual Appliance. ^_^

Just to note, the following string allows the V7 box to see flows, but it is running netflow version 5 and we want to run version 9.
nprobe /i nprobe -n 172.16.2.2:2055 -n 172.16.3.3:2055 -i 0 -i 1 -u 1 -Q 1 -l 5 -t 5 -d 5 -s 5 -V 5

Tony
tonydahle
 
Posts: 4
Joined: Wed Feb 03, 2010 12:18 pm

Re: Scrutinizer Linux Version

Postby mkrygeri » Tue Feb 09, 2010 2:49 pm

Hi Tony,


In the Scrutinizer interface, are you seeing the exporting machine? If so, are there any templates if you click on "Flow Templates" in the devices submenu?
What do you see if you click on "Flow View" in the templates?

I would be interested to see what the export looks like. If you could do a packet capture of the flow data, we can try and see what is happening. As long as the templates are properly formed, Scrutinizer should have no trouble making sense of the data.

Mike Krygeris
mkrygeri
 
Posts: 87
Joined: Tue Aug 02, 2005 8:47 am

Re: Scrutinizer Linux Version

Postby tonydahle » Mon Feb 15, 2010 3:19 pm

Hi Mike,

I am able to see the exporting machine. It is showing up as a V9 interface and it does have two flow templates under it.

Flow View ID 1000 shows up with a large spreadsheet of data 22 columns long and over 300 pages of data.
Flow View ID 1001 shows up as a small table 5 columns long and 6 rows.

I am not seeing a graph of data like V6 when I click on the Inbound or Outbound b/s.

As far as a packet capture, would you like one from both the server and end device or just the server?

I would rather send you that data directly rather than posting here. Can you PM me a contact e-mail?

Thanks,
Tony
tonydahle
 
Posts: 4
Joined: Wed Feb 03, 2010 12:18 pm

Re: Scrutinizer Linux Version

Postby mpatters » Tue Feb 16, 2010 8:43 am

super, thank you
mike [at] plixer.com
Michael Patterson
Scrutinizer Product Manager
(207)324-8805 x222
Bio: viewtopic.php?f=20&t=1296
Blogs: http://www.plixer.com/blog/author/mikeplixercom/
Twitter: http://twitter.com/netflowpm
User avatar
mpatters
 
Posts: 248
Joined: Mon Oct 30, 2006 11:27 pm
Location: Sanford, Maine

Re: Scrutinizer Linux Version

Postby dfx » Mon Sep 26, 2011 11:58 am

Cannot get working linux version (from this blog).

Slackware 13.37 i386.
index.cgi - Net::Pcap::constant() not defined at /</var/www/html/index.cgi>Plixer/Net/Packet.pm line 130
collectd - Net::Pcap::constant() not defined at /</var/www/html/collectd>Plixer/Net/Packet.pm line 130
filed - Net::Pcap::constant() not defined at /</var/www/html/filed>Plixer/Net/Packet.pm line 130

having libpcap 1.1.1.

Help, please.
dfx
 
Posts: 2
Joined: Mon Sep 26, 2011 11:51 am

Re: Scrutinizer Linux Version

Postby pauld » Tue Sep 27, 2011 6:12 am

Hello dfx,

I'm sorry to inform you, but the 6.0.5 Linux version is no longer supported as development on it stopped a few years ago.

However, we are looking into bringing back a Linux version for future releases, so keep checking back in.

Thanks,
Paul
User avatar
pauld
 
Posts: 156
Joined: Mon Jan 04, 2010 10:05 am
Location: Sanford, Maine

Re: Scrutinizer Linux Version

Postby dfx » Tue Sep 27, 2011 8:31 am

Hello, pauld!

Thank you for reply. I'll be waiting for the new release.

But is it really completely impossible to forced to work the old version? May be there are some special requirements (linux distro, library versions)?

Thank you.
dfx
 
Posts: 2
Joined: Mon Sep 26, 2011 11:51 am

Re: Scrutinizer Linux Version

Postby tomp » Tue Sep 27, 2011 8:38 am

Hi dfx,

I would really stay away from version 6. When we do come out with a new Linux version, it won't be an "over the top" upgrade. There are significant improvements from version 6 to 8.6.2 (Current released Windows version).

- Tom
User avatar
tomp
Site Admin
 
Posts: 289
Joined: Wed Jul 27, 2005 9:53 am
Location: Sunny Sanford Maine

Re: Scrutinizer Linux Version

Postby weaverap » Thu Oct 20, 2011 12:33 pm

Just wanting to bump the need for a linux update. We like the ability to use network management tools on Redhat VMs. We want to integrate Zenoss and Plixer tools. Linux is so much easier to harden and much more stable than Windows. If you precompiled an appliance like Zenoss does, the trial exposure would be massive in my opinion.
weaverap
 
Posts: 1
Joined: Thu Oct 20, 2011 12:24 pm


Return to Scrutinizer

Who is online

Users browsing this forum: Google [Bot] and 0 guests

cron

Who is online

In total there is 1 user online :: 1 registered, 0 hidden and 0 guests (based on users active over the past 5 minutes)
Most users ever online was 60 on Thu Jun 25, 2009 9:07 am

Users browsing this forum: Google [Bot] and 0 guests