Skip to content

Repository files navigation

RustFlow

   

RustFlow is a high-performance flow collector written in Rust, with support for NetFlow v5/v9, IPFIX, and sFlow v5.

It can collect flows from the network or PCAP files, normalize them into a common schema, enrich them with external data, and export them as NDJSON, CSV, Protobuf, or Parquet.

Features

  • NetFlow v5 and v9
  • IPFIX
  • sFlow v5
  • Network and PCAP input
  • Raw or normalized flow output
  • NDJSON, CSV, Protobuf and Parquet serialization
  • File rotation and time-based partitioning
  • Flow enrichment using CSV or MaxMind databases
  • Prometheus metrics
  • IPFIX traffic generator
  • Linux IPFIX exporter

Installation

crates.io

cargo install rustflow_cli
rustflow --version

Prebuilt static Linux binaries are also available from the releases page.

Quick Start

Collect NetFlow/IPFIX traffic:

rustflow collect -t netflow -p 9995

Collect sFlow:

rustflow collect -t sflow -p 6343

Write normalized flows to Parquet:

rustflow collect \
  -t netflow \
  -p 9995 \
  -f common \
  -s parquet \
  -o flows.parquet

Read flows from a PCAP file:

rustflow collect -t netflow --pcap capture.pcap

Commands

Command Description
rustflow collect Collect NetFlow, IPFIX, or sFlow traffic
rustflow export Capture network traffic and export it as IPFIX
rustflow generate Generate synthetic IPFIX traffic
rustflow relay Relay UDP flow traffic to another collector

Run:

rustflow <command> --help

for the complete CLI options.

Documentation

License

BSD 3-Clause

About

High-performance, modern flow collector (NetFlow/IPFIX/sFlow) written in Rust

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages