Skip to content

feat(flow): NetFlow/sFlow/IPFIX generators + FlowRecord signal (PIPE-977, BP-474) - #324

Open
Dylan-M wants to merge 1 commit into
mainfrom
dylanmyers/pipe-977-network-flow-records-netflowsflowipfix-generators-and
Open

Dylan-M wants to merge 1 commit into
mainfrom
dylanmyers/pipe-977-network-flow-records-netflowsflowipfix-generators-and

Conversation

@Dylan-M

@Dylan-M Dylan-M commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Proposed Change

Adds a fourth signal type, FlowRecord, with NetFlow/IPFIX/sFlow generation. Key decisions:

  • One protocol-agnostic generator; the output selects wire format and vendor flavor.
  • Vendor flavors (jFlow, NetStream, cflowd, AppFlow, rFlow) are wire-distinct. Vendor and format pairings are validated.
  • Flow projects to OTLP logs via logspb with flow semantic conventions matched to netflowreceiver.

Validated by round-trip against netsampler/goflow2 v2.2.6 (CI test-only).

Checklist
  • Changes are tested
  • CI has passed

@Dylan-M
Dylan-M requested review from a team as code owners September 25, 2026 15:25
Comment thread flow/sflow/sflow.go
binary.BigEndian.PutUint32(fr[0:4], 3) // flow_format = sampled ipv4
binary.BigEndian.PutUint32(fr[4:8], wire.U32(sampledIPv4Len)) // flow_length
d := fr[8:]
binary.BigEndian.PutUint32(d[0:4], wire.U32(f.Bytes)) // length

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

sampled_ipv4.length is one packet's IP length (at most 65,535), but it's set to the flow's total Bytes. A goflow2 collector reported bytes: 911685, packets: 1, sampling_rate: 1024, so each sample counts as about 933 MB.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants