NetFlow Probe/Agent for Linux - SoftFlowD is an alternative to NProbe


I was looking for an alternative to NProbe as a NetFlow Probe/Agent for a CentOS as NProbe is not free and i wanted somehing that i could run as a Probe only and in deamon mode.  After looking at various options, I settled on SoftFlowD as an alternative and thought that I would share with the community how exactly I did it.  It works like a dream for me so enjoy!!!

Installing SoftFlowD as a TCP Flow Based Probe

The following is a description of how we can install a TCP Flow based probe to capture the data going in and out of a Centos Linux server and to export this in NetFlow Version 5 format to a collector for further analysis.

First of ak, we need to ensure that we have a few utilities installed on the server to satisfy the dependencies.

[root@wbcphpxy01 ~]# yum install libtool automake autoconf python-devel


Once these are installed, then let’s get a copy of the softflowd compressed source files:-

[root@wbcphpxy01 ~]# cd /root

[root@wbcphpxy01 ~]#wget

--2013-09-30 11:17:13--

Resolving, 2a00:1450:4001:c02::52

Connecting to||:80... connected.

HTTP request sent, awaiting response... 200 OK

Length: 91939 (90K) [application/x-gzip]

Saving to: âsoftflowd-0.9.9.tar.gzâ

100%[======================================>] 91,939      --.-K/s   in 0.1s

2013-09-30 11:17:13 (673 KB/s) - âsoftflowd-0.9.9.tar.gzâ

Now let’s decompress them:-

[root@wbcphpxy01 ~]# tar -zxvf softflowd-0.9.9.tar.gz








































Now that we have uncompressed the files, let’s change to the relevant directory and then run the configuration script that checks whether you have the relevant programs dependencies such as gcc in place and where those binaries are on your system:-

[root@wbcphpxy01 ~]# cd softflowd-0.9.9

[root@wbcphpxy01 softflowd-0.9.9]# ./configure

checking for gcc... gcc

checking whether the C compiler works... yes

checking for C compiler default output file name... a.out

checking for suffix of executables...

checking whether we are cross compiling... no

checking for suffix of object files... o

checking whether we are using the GNU C compiler... yes

checking whether gcc accepts -g... yes

checking for gcc option to accept ISO C89... none needed

checking for a BSD-compatible install... /usr/bin/install -c

checking how to run the C preprocessor... gcc -E

checking for grep that handles long lines and -e... /bin/grep

checking for egrep... /bin/grep -E

checking for ANSI C header files... yes

checking for sys/types.h... yes

checking for sys/stat.h... yes

checking for stdlib.h... yes

checking for string.h... yes

checking for memory.h... yes

checking for strings.h... yes

checking for inttypes.h... yes

checking for stdint.h... yes

checking for unistd.h... yes

checking net/bpf.h usability... no

checking net/bpf.h presence... no

checking for net/bpf.h... no

checking pcap.h usability... yes

checking pcap.h presence... yes

checking for pcap.h... yes

checking pcap-bpf.h usability... yes

checking pcap-bpf.h presence... yes

checking for pcap-bpf.h... yes

checking for struct sockaddr.sa_len... no

checking for struct ip6_ext.ip6e_nxt... yes

checking for library containing daemon... none required

checking for library containing gethostbyname... none required

checking for library containing socket... none required

checking for pcap_open_live in -lpcap... yes

checking for closefrom... no

checking for daemon... yes

checking for setresuid... yes

checking for setreuid... yes

checking for setresgid... yes

checking for setgid... yes

checking for strlcpy... no

checking for strlcat... no

checking for u_int64_t... yes

checking for int64_t... yes

checking for uint64_t... yes

checking for u_int32_t... yes

checking for int32_t... yes

checking for uint32_t... yes

checking for u_int16_t... yes

checking for int16_t... yes

checking for uint16_t... yes

checking for u_int8_t... yes

checking for int8_t... yes

checking for uint8_t... yes

checking size of char... 1

checking size of short int... 2

checking size of int... 4

checking size of long int... 4

checking size of long long int... 8

configure: creating ./config.status

  1. config.status: creating Makefile
  2. config.status: WARNING:  '' seems to ignore the --datarootdir setting
  3. config.status: creating config.h

Now we need to run the make utility to build a binary executable ready to install, which is customised to your environment:-

[root@wbcphpxy01 softflowd-0.9.9]# make

gcc -g -O2 -DFLOW_SPLAY          -DEXPIRY_RB             -I.   -c -o softflowd.o softflowd.c

gcc -g -O2 -DFLOW_SPLAY          -DEXPIRY_RB             -I.   -c -o log.o log.c

gcc -g -O2 -DFLOW_SPLAY          -DEXPIRY_RB             -I.   -c -o netflow1.o netflow1.c

gcc -g -O2 -DFLOW_SPLAY          -DEXPIRY_RB             -I.   -c -o netflow5.o netflow5.c

gcc -g -O2 -DFLOW_SPLAY          -DEXPIRY_RB             -I.   -c -o netflow9.o netflow9.c

gcc -g -O2 -DFLOW_SPLAY          -DEXPIRY_RB             -I.   -c -o freelist.o freelist.c

gcc -g -O2 -DFLOW_SPLAY          -DEXPIRY_RB             -I.   -c -o convtime.o convtime.c

gcc -g -O2 -DFLOW_SPLAY          -DEXPIRY_RB             -I.   -c -o strlcpy.o strlcpy.c

gcc -g -O2 -DFLOW_SPLAY          -DEXPIRY_RB             -I.   -c -o strlcat.o strlcat.c

gcc -g -O2 -DFLOW_SPLAY          -DEXPIRY_RB             -I.   -c -o closefrom.o closefrom.c

gcc -g -O2 -DFLOW_SPLAY          -DEXPIRY_RB             -I.   -c -o daemon.o daemon.c

gcc  -o softflowd softflowd.o log.o netflow1.o netflow5.o netflow9.o freelist.o convtime.o strlcpy.o strlcat.o closefrom.o daemon.o -lpcap

gcc -g -O2 -DFLOW_SPLAY          -DEXPIRY_RB             -I.   -c -o softflowctl.o softflowctl.c

gcc  -o softflowctl softflowctl.o convtime.o strlcpy.o strlcat.o closefrom.o daemon.o -lpcap

Now that we have a binary ready for installing, we just need to install the application on your system:-

[root@wbcphpxy01 softflowd-0.9.9]# make install

[ -d /usr/local/sbin ] || \./mkinstalldirs /usr/local/sbin

[ -d /usr/local/share/man/man8 ] || \./mkinstalldirs /usr/local/share/man/man8

/usr/bin/install -c -m 0755 -s softflowd /usr/local/sbin/softflowd

/usr/bin/install -c -m 0755 -s softflowctl /usr/local/sbin/softflowctl

/usr/bin/install -c -m 0644 softflowd.8 /usr/local/share/man/man8/softflowd.8

/usr/bin/install -c -m 0644 softflowctl.8 /usr/local/share/man/man8/softflowctl.8

[root@wbcphpxy01 softflowd-0.9.9]#

Now that we have a working copy of softflowd on the system, we can review the help file for the application by typing the following:-

[root@wbcphpxy01 ~]# softflowd -h

-i or -r option not specified.

Usage: softflowd [options] [bpf_program]

This is softflowd version 0.9.9. Valid commandline options:

  -i [idx:]interface Specify interface to listen on

  -r pcap_file       Specify packet capture file to read

  -t timeout=time    Specify named timeout

  -m max_flows       Specify maximum number of flows to track (default 8192)

  -n host:port       Send Cisco NetFlow(tm)-compatible packets to host:port

  -p pidfile         Record pid in specified file

                     (default: /var/run/

  -c pidfile         Location of control socket

                     (default: /var/run/softflowd.ctl)

  -v 1|5|9           NetFlow export packet version

  -L hoplimit        Set TTL/hoplimit for export datagrams

  -T full|proto|ip   Set flow tracking level (default: full)

  -6                 Track IPv6 flows, regardless of whether selected

                     NetFlow export protocol supports it

  -d                 Don't daemonise (run in foreground)

  -D                 Debug mode: foreground + verbosity + track v6 flows

  -s sampling_rate   Specify periodical sampling rate (denominator)

  -h                 Display this help

Now, we should be able to run the software in Debug mode in the foreground using the following command to ensure that we see the relevant messages (especially error messages):-

[root@wbcphpxy01 ~]# softflowd -D -v 5 -i eth0 -n -T full

Using eth0 (idx: 0)

softflowd v0.9.9 starting data collection

Exporting flows to []:iop

ADD FLOW seq:1 []:1335 <> []:22 proto:6

ADD FLOW seq:2 []:58374 <> []:1900 proto:17

ADD FLOW seq:3 []:0 <> []:0 proto:2

ADD FLOW seq:4 []:0 <> []:0 proto:2


In the above example, the following explains each of the switches I have used:-

-D                                           Debug mode, which bring this to the foreground

-v 5                                         Version 5 of Netflow

-i eth0                                   The Interface number

-n         The target host IP address and port number of the collector/analyser

-T full                                     All protocols

Now running this is Debug mode is useful if you want to make sure that is working but it more useful to have this running in the background so the way we do that is to remove the –D statement in the option like such and you will just see the command prompt come back:-

[root@wbcphpxy01 ~]# softflowd -v 5 -i eth0 -n -T full

[root@wbcphpxy01 ~]#

You can still see that the flows are being “recorded” and that they are being exported in NetFlow version 5 and set to in this case using destination port 2055.  This is done using a utility such as TCPDUMP:-

[root@wbcphpxy01 ~]# tcpdump -n –v dst port 2055

listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes

14:14:01.426775 IP > UDP, length 312

14:15:01.185508 IP > UDP, length 408

14:16:01.944233 IP > UDP, length 168

Now all this is fine, but it really only becomes useful if we can stop/start and restart the application like a service and have this enabled after the server has had a reboot.  To do this we edit a file called /etc/init.d/softflowd and empty the following contents into the file and save it:-

#! /bin/bash


# chkconfig: 2345 80 30

# description: SoftFlow Deamon Service


# Provides: SOFTFLOWD

# Short-Description: Start/Stop/Restart SOFTFLOWD TCP Flow Probe



# SOFTFLOWD This init.d script is used to start SOFTFLOWD.









start_SOFTFLOWD() {

${SOFTFLOWD} ${OPTIONS} > /dev/null &

return 1


stop_SOFTFLOWD() {

if [ -f ${PID_FILE} ]; then

kill `cat ${PID_FILE}` 2>1 /dev/null

\rm ${PID_FILE}




case "$1" in


echo -n "Starting SOFTFLOWD"


echo " Done."



echo -n "Stopping SOFTFLOWD"


echo " Done."



echo -n "Restarting SOFTFLOWD"


sleep 1


echo " Done."



echo "Usage: /etc/init.d/SOFTFLOWD {start|stop|restart}"

exit 1


exit 0

After saving the file, we need to change the file permissions to:-

[root@wbcphpxy01 ~]# chmod 755 /etc/init.d/softflowd

Now let’s make the script a loadable initialisation script as part of the “service <application name> start” function by adding this with the chkconfig command:-

[root@wbcphpxy01 ~]# chkconfig --add softflowd

If you need to remove the script from being initiated at boot up as a service, then issue the following:-

[root@wbcphpxy01 ~]# chkconfig --remove softflowd

Finally, let’s start the service:-

[root@wbcphpxy01 ~]# service softflowd start


  • How were you able to solve the duplicate index numbers on the flow data which returns the following error? It seems softflowd sends the same interface index ID number for both in and out interfaces, which as one might imagine confuses NTA.

    NTA Error.png

    NetFlow Data Export Not Enabled

    NTA is receiving NetFlow traffic from a wrong interface (restricted or unsupported).
    "NetFlow data export on device x.x.x.x is not enabled. If you cannot see NetFlow data from the device in NTA, make sure the device is configured to export NetFlow. » Learn more."

    The event is generated when both indexes are 0. This can happen in two cases:

    • Incorrectly configured device. For more information about configuring the device, see Setting Up Network Devices to Export NetFlow Data.
    • If data from the node are visible in NTA, it is safe to ignore this event. In this case, this event only makes you aware of internal node configuration.
  • Does this actually work? It would appear so from your comments but I'm not getting any flows recognised by Solarwinds NTA even though Wireshark sees the packets arriving.

    It would appear the there is a problem with the InputInt and OutputInt fields.

    pdu 1/7




        InputInt: 0

        OutputInt: 0

        Packets: 11

        Octets: 7944

        [Duration: 29.514000000 seconds]

        SrcPort: 389

        DstPort: 55995

        Padding: 00

        TCP Flags: 0x1e

        Protocol: TCP (6)

        IP ToS: 0x00

        SrcAS: 0

        DstAS: 0

        SrcMask: 0 (prefix:

        DstMask: 0 (prefix:

        Padding: 0000

  • By sending same interfaces id of zero is softflowd not following the standard?  Or is it nta that is out of standard?

    As I am able to use softflowd with other netflow collectors like manage engine and prtg.

  • hi

    i am still looking for its solution..

    is softlowd not compatible with orion netflow collectors ?

  • hope someone from Orion chimes in ..

  • I got this working with no problem. One of the things I did differently from this post is setting a time limit of 5 minutes and I also included the interface index number to the -i flag for softflow.







    OPTIONS="-v ${VERSION} -i ${INTERFACE} -n ${COLLECTOR}:${CPORT} -T full -p ${PID_FILE} -t general=5m"