Gentoo Archives: gentoo-server

From: Wayne Doyle <wayne.doyle@××××××××××××.com>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] Network Monitoring Packages eg:ntop
Date: Thu, 22 Dec 2005 21:25:51
Message-Id: 43AB1907.5040208@voiceperfect.com
In Reply to: Re: [gentoo-server] Network Monitoring Packages eg:ntop by "James M. Cook"
1 Hi Guys,
2
3 Sounds like a job for ipaudit.
4 http://ipaudit.sourceforge.net/ipaudit-web/
5
6 I didn't like ipaudit-web so I just used ipaudit it has a rather neat
7 direct dump into mysql.
8 well worth considering.
9
10 Wayne
11
12 James M. Cook wrote:
13
14 >On Thursday 22 December 2005 8:41 am, Ow Mun Heng wrote:
15 >
16 >
17 >>Hi All,
18 >>
19 >>Just want to see if anyone has any good info to share.
20 >>
21 >>What I want: (not necessary host availability/polling)
22 >>
23 >>Network monitoring/network traffic analyser which is something like ntop
24 >>which shows IP traffic in (from where) and out (to where) as well as top
25 >>talkers, top ports etc. This is basically to determine whats happening
26 >>with my network and who's been hogging the bandwidth etc. (time for some
27 >>wrist slapping!!)
28 >>
29 >>And preferably it logs into a Mysql/Postgressql database which can be
30 >>later dissected for analysis.
31 >>
32 >>I've looked at opennms - http://bugs.gentoo.org/show_bug.cgi?id=51441
33 >>which seems to be able to do it.
34 >>
35 >>I've also looked at jffnms, (which used to be in portage? searched
36 >>through the archives and it seems it was previously) but it seems to
37 >>only be able to look at host/server availability.
38 >>
39 >>Looked at argus, it seems to have the features for Traffic Flow Analysis
40 >>but it does not support (AFAICT) for logging into a DB.(The FAQ states
41 >>answer is coming)
42 >>
43 >>Zabbix is another package but seems like it too provides for
44 >>client/server availability etc. Doesn't do much for my needs.
45 >>
46 >>I initially looked at ntop, then found out that it no longer uses a SQL
47 >>database for it's backend data collection, it now uses rrdtool. I've got
48 >>some stupid question, I understand that RRDtool is a good thing since
49 >>it's like a never growing DB, but frankly, just how many days/years of
50 >>data can it hold? What's the limit etc? I don't seem to be able to
51 >>locate a FAQ about that one particular point.
52 >>
53 >>Appreciate some comments.
54 >>
55 >>Thanks
56 >>
57 >>
58 >>
59 >
60 >I've evaluated all the packages you've listed but had completely forgotten
61 >about ntop (which I'm playing with now, fantastic). I'm not sure any of them
62 >are going to give you what you want.
63 >I didn't see any information about Traffic Flow Analysis on argus' website, do
64 >you have that URL?
65 >Here's what I found for each:
66 >opennms - nice, but uses tomcat since it's java based. Seemed to generate the
67 >heaviest load on the server. Not knowing a whole lot about tomcat and using
68 >tomcat4, which is not available in portage, made setup a little tricky for
69 >me. Didn't see any graphing capabilities either.
70 >
71 >jffnms - this was my choice for a while. Then I tried to add a new OID and
72 >couldn't figure it out. I found the montoring interface was good but you
73 >cannot reliably use the back button. The admin interface is a little
74 >confusing. Documentation is sparse in many areas and development appears to
75 >have stopped.
76 >
77 >argus - this is my new choice. I like the simple web interface and the
78 >configuration is pretty straightforward. I'm actually creating a script to
79 >convert my old monitoring sw config to argus. Working at an ASP requires
80 >monitoring website performance which appears to be the most straightforward
81 >with argus. The graphs aren't as good as some other packages.
82 >
83 >zabbix - I liked the newer version of this software looks (I think 1.1b2 was
84 >the version) with it's revamped web frontend. I didn't care for installing
85 >remote agents on all my servers and administration seemed confusing to me.
86 >
87 >I've also tried midas (which appears to be dead and similar to zabbix) and
88 >cacti with the threshold plugin. I really like cacti but didn't care for the
89 >threshold plugin. It felt like NMS functionality was being bolted on top of
90 >cacti. It works but not for my purposes.
91 >
92 >It seems to me that none of these packages are perfect fits. For me argus
93 >seems have come the closest. My main issue is there is not web interface to
94 >update the config which is available in most of the others. This should only
95 >become an issue when I start to have others maintain the system. :)
96 >
97 >In the end I'll probably end up using a few pieces of software to address my
98 >monitoring needs.
99 >
100 >James
101 >
102 >
103 >
104
105 --
106 gentoo-server@g.o mailing list