#netflow #ebpf #probe

deprecated bin+lib nfprobe

A netflow probe using ebpf

1 unstable release

0.0.1 Jul 18, 2021

#10 in #netflow

MIT/Apache

71KB
991 lines

nfprobe

A netflow probe using bpf.

Features

  • data enrichment
  • output

TODO

kprobe/kretprobe can run on different processors, as a function could resume on a new processor.

Can a function resume on a new thread?

ktime does not count for hibernation.

Dependencies

~200KB