This is an old revision of the document!
# apt install nfdump # ps auxwww | grep nfcapd # nfdump -o csv -R /var/cache/nfdump/ | head -n1
ts,te,td,sa,da,sp,dp,pr,flg,fwd,stos,ipkt,ibyt,opkt,obyt,in,out,sas,das,smk,dmk,dtos,dir,nh,nhb,svln,dvln,ismc,odmc,idmc,osmc,mpls1,mpls2,mpls3,mpls4,mpls5,mpls6,mpls7,mpls8,mpls9,mpls10,cl,sl,al,ra,eng,exid,tr
# man nfdump /OUTPUT FORMATS # nfdump -o csv -q -R /var/cache/nfdump/ | grep 192.168.X.128 # service nfdump restart # nfdump -o csv -q -R /var/cache/nfdump/ 'proto tcp and src ip 192.168.X.128'