Netflow Stats for 07/07/2003
Connie Logg
Tue Jul 8 00:35:01 PDT 2003


STATS: total records = 8871428; missed records = 0; percent missed = 0.00;
Any link terminated with an '*', is only visible within SLAC.
PROTOCOLS APPLICATION BUCKETS SLAC PROGRAMS
ProtocolTotal RecsTotal FlowsTotal PktsTotal Bytes
ALL 8.87 M 9.11 M 1.42 G 1.36 T
TCP 5.48 M
61.78 %
5.60 M
61.41 %
1.39 G
97.76 %
1.35 T
98.74 %
UDP 3.04 M
34.22 %
3.10 M
34.04 %
20.83 M
1.47 %
14.02 G
1.03 %
GRE 3.64 K
0.04 %
3.66 K
0.04 %
6.42 M
0.45 %
2.51 G
0.18 %
ICMP 351.08 K
3.96 %
0.41 M
4.51 %
4.50 M
0.32 %
680.38 M
0.05 %
BucketRecordsFlowsPacketsBytes
BULK* 298.68 K
3.37 %
337.44 K
3.70 %
1.00 G
70.49 %
988.39 G
72.47 %
DATABASE* 435.00
0.00 %
445.00
0.00 %
94.11 K
0.01 %
72.07 M
0.01 %
GRID* 16.50 K
0.19 %
16.51 K
0.18 %
127.42 K
0.01 %
47.63 M
0.00 %
INTERACTIVE* 805.00
0.01 %
864.00
0.01 %
47.58 K
0.00 %
4.53 M
0.00 %
MAIL* 411.97 K
4.64 %
419.08 K
4.60 %
4.90 M
0.34 %
1.91 G
0.14 %
OTHER* 317.93 K
3.58 %
338.05 K
3.71 %
30.38 M
2.14 %
19.10 G
1.40 %
SERVICES* 3.33 M
37.52 %
3.49 M
38.34 %
292.19 M
20.58 %
292.17 G
21.42 %
WWW* 4.47 M
50.41 %
4.48 M
49.19 %
89.77 M
6.32 %
61.04 G
4.48 %
ProgramRecordsFlowsPacketsBytes
HEP 8.01 M
90.33 %
8.17 M
89.60 %
1.39 G
97.87 %
1.34 T
98.52 %
OTHER 0.00
0.00 %
0.00
0.00 %
0.00
0.00 %
0.00
0.00 %
SSRL 857.81 K
9.67 %
948.16 K
10.40 %
30.20 M
2.13 %
20.13 G
1.48 %

Note: The data links are to the data files used by Gnuplot to plot the data. This data can be copied and pasted into the Excel application, and by exercising Excel's'Data'=>'Text to columns', the blank separated data can be formatted for further manipulation by Excel.

Graphs show one point per day. TCP ~= ALL so TCP data overplots the ALL.
Protocol Raw Data Historical
.
The 'Buckets' have been defined by the 'Micsmon' Committee, and are detailed below.
Bucket Raw Data Historical
.
SLAC WAN traffic can be broken down into 2 identifiable areas. There is the High Energy Physics (HEP) program and the Stanford Synchrotron Radiation Laboratory (SSRL).
Program Raw Data Historical


Top Level Domains

This graph shows the history of traffic volume for some of our collaborators aroung the world. The collaborators plotted are listed in the file /afs/slac/package/netmon/netflow/src/topdom-hist.cfg. The blank separated data is available here

In the following two graphs, in and out traffic are lumped together to calculate the total traffic between SLAC and the internet.

Characterizing the Traffic and Flows


Bucket Specifications

Note: The netflow records are examined and classified by the following table. No attempt is made to disguish 'spoofed' or phony port accesses from the genuine ones.

Bucket TypeMembers
BULKTCP Applications:
ftp (20,21), ssh (22), bbftp (5020-5022), bbcp (5031), nfs (2049),
UDP Applications:
afs (0,7000,7001,7002,7003,7004,7005,7006,7007,7008,7009), nfs (2049),
Specified Nodes:
afs-nodes,datamove-nodes
DATABASETCP Applications:
postgres (5432), sqlnet (1521), oracle (1525,1527,1529), ingres (1524), objectivity (6780,6779,1992,1993,1994,1995,1996,1997,1998,3333),
Specified Nodes:
objectivity-nodes
GRIDTCP Applications:
grid-gatekeeper (2119), grid-gsiftp (2811), grid-ldaps (636), grid-mds-giis (2135), grid-gsiftpdata (6100-6299),
INTERACTIVETCP Applications:
klogin (543), kshell (544), rlogin (513), shell (514), telnet (23),
MAILTCP Applications:
imap4 (143), imaps (993), pop2 (109), pop3 (110), smtp (25),
Specified Nodes:
mail-nodes
OTHERTCP Applications:
other (),
UDP Applications:
other (),
SERVICESTCP Applications:
X11 (6000-6006), bgp (179), discard (9), dns (53), echo (7), exec (512), finger (79), ident (113), portmap (111), netbios (137,138,139), ntp (123), printer (515), tftp (69), time (37), ldap (389), wins (42), iperf (5000-5012),
UDP Applications:
dns (53), portmap (111),
Specified Nodes:
netmon-nodes,visitor
WWWTCP Applications:
irc (6666,6667), www (80,443,119,591,8080,8088),

SLACONLY Analysis

A note on how this is created:


Please provide feedback to designing author: Connie Logg,