nfdump
A suite of command-line tools for collecting, processing and analyzing NetFlow, IPFIX and sFlow data.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
1 more ways to get nfdump
Package managers
- Homebrew
brew install nfdump
About nfdump
nfdump is a set of tools for receiving flow records from routers, switches and other network devices, storing them, and querying them afterwards. It handles NetFlow, IPFIX and sFlow.
The tools support filtering, aggregation and enrichment of flow data, including geolocation, so you can answer questions such as which hosts used the most bandwidth or which connections went to a given address. It suits network administrators who need traffic accounting and forensic analysis from the command line.
Strengths
- Supports NetFlow, IPFIX and sFlow
- Filtering and aggregation of stored flow records
- Geolocation enrichment of flow data
- Long development history
Limitations
- Command-line only, with no built-in graphical interface
- Needs network devices configured to export flow data
Details
- Pricing
- FreeFree and open source under a BSD license.
- License
- BSD
- Developer
- Peter Haag
- Platforms
- Linux, Self-hosted, Command line
- How it runs
- Downloadable app, Self-hosted
- Account
- Not required
- Works offline
- Yes
- Best suited for
- Network administrators analysing traffic flows from routers and switches
- Categories
- Network tools
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to nfdump
Compare allSoftware that can replace nfdump for an important use case, and what changes if you switch.
pmacct
A set of passive network monitoring tools that collect NetFlow, IPFIX, sFlow, packet and BGP data.
pmacct also collects NetFlow, IPFIX and sFlow and adds BGP, BMP and RPKI routing data, configured through text files with many keys.
GoFlow2
A NetFlow, IPFIX and sFlow collector written in Go that normalises flow data into one format.
GoFlow2 is a Go collector that normalises NetFlow, IPFIX and sFlow for high volumes, but needs separate storage and dashboards for analysis.
Akvorado
Self-hosted flow collector, enricher and visualizer for NetFlow, IPFIX and sFlow traffic data.
Akvorado adds flow enrichment and a web console for exploring traffic, at the cost of deploying and maintaining several components.
ntopng
Web-based network traffic probe that shows real-time and historical flows by host, protocol and application.
ntopng provides a web interface with application detection and historical traffic, but some features need a paid licence and flow collection works via nProbe.
Similar software
Related functionality, not necessarily a direct replacement.
Arkime
Store and search captured network traffic through a web interface.
Malcolm
A self-hosted network traffic analysis suite that turns PCAP files, Zeek logs and Suricata alerts into searchable dashboards.
vnStat
A console network traffic monitor for Linux and BSD that logs interface usage over time.
IPTraf-ng
A console-based network monitor for Linux that shows live IP traffic statistics by connection and interface.