[Flow-tools] nfilter date problem (bug?)

Benjamin Bach benjaoming at gmail.com
Sat Jun 16 16:37:39 EDT 2007


Dear all,

I'm having no difficulties with nfilter, only when I scan flows in
intervals where I'm totally sure that there has never been any
traffic. Currently I'm working on flows generated up until May 30th,
so this extraction (I didn't include the filter and command line
options since there isn't any errors in them.. or I find it highly
unlikely) should generate no data... still it does and the date fields
seem really weird:

start-date: ge June 1, 2007 00:00:00
end-date: lt June 2, 2007 00:00:00

Sif  SrcIPaddress     DIf  DstIPaddress      Pr SrcP DstP  Pkts  Octets
 StartTime          EndTime             Active   B/Pk Ts Fl

0000 83.221.155.11    0001 62.58.50.220      11 8108 35    1111       101073
 0707.08:56:56.050  0518.16:28:34.524   2065.770 90  00 00

0000 83.221.155.11    0001 62.119.28.229     11 8108 35    60         5133
 0707.09:00:29.970  0518.16:30:02.317   1939.643 85  00 00

...it goes on like that. It finds lots of flows with these weird
starting dates. How's that possible?

Sincerely,
Benjamin


More information about the Flow-tools mailing list