Skip to content

Repository files navigation

RustFlow

RustFlow is a high-performance flow collector written in Rust, with support for NetFlow v5/v9, IPFIX, and sFlow v5.

It can collect flows from the network or PCAP files, normalize them into a common schema, enrich them with external data, and export them as NDJSON, CSV, Protobuf, or Parquet.

Features

  • NetFlow v5 and v9
  • IPFIX
  • sFlow v5
  • Network and PCAP input
  • Raw or normalized flow output
  • NDJSON, CSV, Protobuf and Parquet serialization
  • File rotation and time-based partitioning
  • Flow enrichment using CSV or MaxMind databases
  • Prometheus metrics
  • IPFIX traffic generator
  • Linux IPFIX exporter

Installation

crates.io

cargo install rustflow_cli
rustflow --version

Prebuilt static Linux binaries are also available from the releases page.

Quick Start

Collect NetFlow/IPFIX traffic:

rustflow collect -t netflow -p 9995

Collect sFlow:

rustflow collect -t sflow -p 6343

Write normalized flows to Parquet:

rustflow collect \
-t netflow \
-p 9995 \
-f common \
-s parquet \
-o flows.parquet

Read flows from a PCAP file:

rustflow collect -t netflow --pcap capture.pcap

Commands

CommandDescription
rustflow collectCollect NetFlow, IPFIX, or sFlow traffic
rustflow exportCapture network traffic and export it as IPFIX
rustflow generateGenerate synthetic IPFIX traffic

Run:

rustflow <command> --help

for the complete CLI options.

Documentation

License

BSD 3-Clause

About

High-performance, modern flow collector (NetFlow/IPFIX/sFlow) written in Rust

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages