Alternatives to nfdump
A suite of command-line tools for collecting, processing and analyzing NetFlow, IPFIX and sFlow data. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
nfdump
A suite of command-line tools for collecting, processing and analyzing NetFlow, IPFIX and sFlow data.
Replacements
Listings that take over the same core job as nfdump.
pmacct
A set of passive network monitoring tools that collect NetFlow, IPFIX, sFlow, packet and BGP data.
pmacct also collects NetFlow, IPFIX and sFlow and adds BGP, BMP and RPKI routing data, configured through text files with many keys.
GoFlow2
A NetFlow, IPFIX and sFlow collector written in Go that normalises flow data into one format.
GoFlow2 is a Go collector that normalises NetFlow, IPFIX and sFlow for high volumes, but needs separate storage and dashboards for analysis.
Akvorado
Self-hosted flow collector, enricher and visualizer for NetFlow, IPFIX and sFlow traffic data.
Akvorado adds flow enrichment and a web console for exploring traffic, at the cost of deploying and maintaining several components.
ntopng
Web-based network traffic probe that shows real-time and historical flows by host, protocol and application.
ntopng provides a web interface with application detection and historical traffic, but some features need a paid licence and flow collection works via nProbe.
Similar software
Related functionality, not a direct replacement.
Arkime
Store and search captured network traffic through a web interface.
Malcolm
A self-hosted network traffic analysis suite that turns PCAP files, Zeek logs and Suricata alerts into searchable dashboards.
vnStat
A console network traffic monitor for Linux and BSD that logs interface usage over time.
IPTraf-ng
A console-based network monitor for Linux that shows live IP traffic statistics by connection and interface.