nfdump Logo

nfdump

0
Free
Visit Website

nfdump is a toolset for collecting and processing netflow/ipfix and sflow data, sent from netflow/sflow compatible devices. It contains several collectors to collect flow data and can process and list flows in many different output formats, creating a wide range of statistics. It also has a powerful flow filter and can aggregate flows according to a user-defined number of elements. nfdump can enrich the listing of flows with geo location information and AS information, and can read and write flow files in various formats. It is compatible with nfdump-1.6.18 and can read files created with earlier versions. nfdump is now a multi-threaded program and uses parallel threads for reading, writing, and processing flows, as well as for sorting. It supports flexible length fields for netflow v9 and IPFIX, and has improved packet processing with nfpcapd. nfdump has new programs such as geolookup, which allows enriching IP addresses with country codes/locations and adding potential missing AS information. It also supports NSEL/ASA and NEL/NAT event logging.

FEATURES

ALTERNATIVES

A log management solution that optimizes SIEM performance, provides rapid search and troubleshooting, and meets compliance requirements.

Commercial

A framework for generating log events without the need for infrastructure, allowing for simple, repeatable, and randomized log event creation.

Free

Sysdig is a system visibility tool with native container support.

Free

A dynamic GUI for advanced log analysis, allowing users to execute SQL queries on structured log data.

Free

Standalone SIGMA-based detection tool for EVTX, Auditd, Sysmon for Linux, XML or JSONL/NDJSON Logs.

Free

Serverless, real-time data analysis framework for incident detection and response.

Free

A community-led project focused on standardizing security event logs.

Free

ElastAlert is a framework for alerting on anomalies in Elasticsearch data.

Free