Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

ย 

History

150 Commits
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

InMon sFlow v5 Parser

CI Status Crates.io Docs Codecov License

A dependency-free Rust library for parsing InMon sFlow version 5 datagrams.

Implementation Status

Main sFlow v5 specification, extensions and discussions are implemented.

Each implemented flow and counter record is covered by a unit test and validated against the official sFlow specification documents.

The flows and counters types tables below list all sFlow structure numbers as defined in the official sFlow structure registry.

Status Legend:

  • โœ… Implemented
  • โฌœ Not implemented
  • ๐Ÿชฆ Deprecated

Specifications

The main specification is sFlow Version 5 from 2004, but many extensions have been published since to support additional monitoring use cases.

Year Specification Description Status
2004 sFlow Version 5 Core protocol, base flow and counter records โœ…
2007 sFlow 802.11 Structures Wireless/802.11 monitoring extensions โœ…
2010 sFlow Host Structures Host and virtual machine performance metrics โœ…
2011 sFlow HTTP Structures HTTP performance metrics โœ…
2011 sFlow Java Virtual Machine Structures JVM performance metrics โœ…
2011 sFlow Memcache Structures Memcache performance metrics โœ…
2012 sFlow NVML GPU Structures NVIDIA GPU performance, status, and health โœ…
2012 sFlow Application Structures Application resource monitoring โœ…
2012 sFlow LAG Counters Structure IEEE 802.1AX Link Aggregation (LACP) โœ…
2012 sFlow Tunnel Structures Encapsulation/decapsulation (VXLAN, GRE, etc.) โœ…
2012 sFlow Port NAT Structures Port-based NAT mapping โœ…
2013 sFlow InfiniBand Structures InfiniBand network monitoring โœ…
2014 sFlow OpenFlow Structures OpenFlow port monitoring โœ…
2015 sFlow Host TCP/IP Counters Host IP, ICMP, TCP, and UDP counters โœ…
2015 sFlow Broadcom ASIC Table Utilization Hardware table utilization for Broadcom ASICs โœ…
2015 sFlow Broadcom Buffer Utilization Buffer utilization for Broadcom switches โœ…
2016 sFlow Optical Interface Structures Pluggable optical modules (SFP, QSFP, etc.) โœ…
2020 sFlow Dropped Packet Notification Reports on dropped packets with reason codes โœ…
2021 sFlow Transit Delay Structures Delay and queue depth for sampled packets โœ…

Note: see sFlow Errata for corrections to published specifications.

Sample Types

sFlow datagrams contain sample records. Each sample record has a format type that determines its structure:

Enterprise Format Name Specification Status
0 1 Flow Sample sFlow v5 โœ…
0 2 Counters Sample sFlow v5 โœ…
0 3 Flow Sample Expanded sFlow v5 โœ…
0 4 Counters Sample Expanded sFlow v5 โœ…
0 5 Discarded Packet sFlow Drops โœ…
4300 1002 Custom Metrics sFlow-RT โœ…
4300 1003 Custom Flow Metrics sFlow-RT โœ…

Each sample contains one or more flow records (for flow samples) or counter records (for counter samples).

Flow Records

Enterprise Format Name Specification Status
0 1 Sampled Header sFlow v5 โœ…
0 2 Sampled Ethernet sFlow v5 โœ…
0 3 Sampled IPv4 sFlow v5 โœ…
0 4 Sampled IPv6 sFlow v5 โœ…
0 1001 Extended Switch sFlow v5 โœ…
0 1002 Extended Router sFlow v5 โœ…
0 1003 Extended Gateway (BGP) sFlow v5 โœ…
0 1004 Extended User sFlow v5 โœ…
0 1005 Extended URL (deprecated) sFlow v5 โœ… ๐Ÿชฆ
0 1006 Extended MPLS sFlow v5 โœ…
0 1007 Extended NAT sFlow v5 โœ…
0 1008 Extended MPLS Tunnel sFlow v5 โœ…
0 1009 Extended MPLS VC sFlow v5 โœ…
0 1010 Extended MPLS FEC sFlow v5 โœ…
0 1011 Extended MPLS LVP FEC sFlow v5 โœ…
0 1012 Extended VLAN Tunnel sFlow v5 โœ…
0 1013 Extended 802.11 Payload sFlow 802.11 โœ…
0 1014 Extended 802.11 RX sFlow 802.11 โœ…
0 1015 Extended 802.11 TX sFlow 802.11 โœ…
0 1016 Extended 802.11 Aggregation sFlow 802.11 โœ…
0 1017 Extended OpenFlow v1 (deprecated) sFlow OpenFlow Draft โœ… ๐Ÿชฆ
0 1018 Extended Fibre Channel RFC 4625 โœ…
0 1019 Extended Queue Length sFlow Discussion โœ…
0 1020 Extended NAT Port sFlow Port NAT โœ…
0 1021 Extended L2 Tunnel Egress sFlow Tunnel โœ…
0 1022 Extended L2 Tunnel Ingress sFlow Tunnel โœ…
0 1023 Extended IPv4 Tunnel Egress sFlow Tunnel โœ…
0 1024 Extended IPv4 Tunnel Ingress sFlow Tunnel โœ…
0 1025 Extended IPv6 Tunnel Egress sFlow Tunnel โœ…
0 1026 Extended IPv6 Tunnel Ingress sFlow Tunnel โœ…
0 1027 Extended Decapsulate Egress sFlow Tunnel โœ…
0 1028 Extended Decapsulate Ingress sFlow Tunnel โœ…
0 1029 Extended VNI Egress sFlow Tunnel โœ…
0 1030 Extended VNI Ingress sFlow Tunnel โœ…
0 1031 Extended InfiniBand LRH sFlow InfiniBand โœ…
0 1032 Extended InfiniBand GRH sFlow InfiniBand โœ…
0 1033 Extended InfiniBand BTH sFlow InfiniBand โœ…
0 1034 Extended VLAN In sFlow Discussion โœ…
0 1035 Extended VLAN Out sFlow Discussion โœ…
0 1036 Extended Egress Queue sFlow Drops โœ…
0 1037 Extended ACL sFlow Drops โœ…
0 1038 Extended Function sFlow Drops โœ…
0 1039 Extended Transit Delay sFlow Transit โœ…
0 1040 Extended Queue Depth sFlow Transit โœ…
0 1041 Extended HW Trap host-sflow Implementation โœ…
0 1042 Extended Linux Drop Reason host-sflow Implementation โœ…
0 2000 Transaction sFlow Discussion โœ…
0 2001 Extended NFS Storage Transaction sFlow Discussion โœ…
0 2002 Extended SCSI Storage Transaction sFlow Discussion โœ…
0 2003 Extended HTTP Transaction sFlow Discussion โœ…
0 2100 Extended Socket IPv4 sFlow Host โœ…
0 2101 Extended Socket IPv6 sFlow Host โœ…
0 2102 Extended Proxy Socket IPv4 sFlow HTTP โœ…
0 2103 Extended Proxy Socket IPv6 sFlow HTTP โœ…
0 2200 Memcache Operation sFlow Memcache โœ…
0 2201 HTTP Request (deprecated) sFlow Discussion โœ… ๐Ÿชฆ
0 2202 App Operation sFlow Application โœ…
0 2203 App Parent Context sFlow Application โœ…
0 2204 App Initiator sFlow Application โœ…
0 2205 App Target sFlow Application โœ…
0 2206 HTTP Request sFlow HTTP โœ…
0 2207 Extended Proxy Request sFlow HTTP โœ…
0 2208 Extended Nav Timing sFlow Discussion โœ…
0 2209 Extended TCP Info sFlow Discussion โœ…
0 2210 Extended Entities sFlow Discussion โœ…
4413 1 BST Egress Queue sFlow Broadcom โœ…

Counter Records

Enterprise Format Name Specification Status
0 1 Generic Interface sFlow v5 โœ…
0 2 Ethernet Interface sFlow v5 โœ…
0 3 Token Ring sFlow v5 โœ…
0 4 100BaseVG Interface sFlow v5 โœ…
0 5 VLAN sFlow v5 โœ…
0 6 IEEE 802.11 Counters sFlow 802.11 โœ…
0 7 LAG Port Stats sFlow LAG โœ…
0 8 Slow Path Counts sFlow Discussion โœ…
0 9 InfiniBand Counters sFlow InfiniBand โœ…
0 10 Optical SFP/QSFP sFlow Optics โœ…
0 1001 Processor sFlow v5 โœ…
0 1002 Radio Utilization sFlow 802.11 โœ…
0 1003 Queue Length sFlow Discussion โœ…
0 1004 OpenFlow Port sFlow OpenFlow โœ…
0 1005 OpenFlow Port Name sFlow OpenFlow โœ…
0 2000 Host Description sFlow Host โœ…
0 2001 Host Adapters sFlow Host โœ…
0 2002 Host Parent sFlow Host โœ…
0 2003 Host CPU sFlow Host โœ…
0 2004 Host Memory sFlow Host โœ…
0 2005 Host Disk I/O sFlow Host โœ…
0 2006 Host Network I/O sFlow Host โœ…
0 2007 MIB2 IP Group sFlow Host TCP/IP โœ…
0 2008 MIB2 ICMP Group sFlow Host TCP/IP โœ…
0 2009 MIB2 TCP Group sFlow Host TCP/IP โœ…
0 2010 MIB2 UDP Group sFlow Host TCP/IP โœ…
0 2100 Virtual Node sFlow Host โœ…
0 2101 Virtual CPU sFlow Host โœ…
0 2102 Virtual Memory sFlow Host โœ…
0 2103 Virtual Disk I/O sFlow Host โœ…
0 2104 Virtual Network I/O sFlow Host โœ…
0 2105 JVM Runtime sFlow JVM โœ…
0 2106 JVM Statistics sFlow JVM โœ…
0 2200 Memcache Counters (deprecated) sFlow Discussion โœ… ๐Ÿชฆ
0 2201 HTTP Counters sFlow HTTP โœ…
0 2202 App Operations sFlow Application โœ…
0 2203 App Resources sFlow Application โœ…
0 2204 Memcache Counters sFlow Memcache โœ…
0 2206 App Workers sFlow Application โœ…
0 2207 OVS DP Stats sFlow Discussion โœ…
0 3000 Energy sFlow Discussion โœ…
0 3001 Temperature sFlow Discussion โœ…
0 3002 Humidity sFlow Discussion โœ…
0 3003 Fans sFlow Discussion โœ…
4413 1 Broadcom Device Buffer sFlow Broadcom โœ…
4413 2 Broadcom Port Buffer sFlow Broadcom โœ…
4413 3 Broadcom ASIC Tables sFlow Broadcom โœ…
5703 1 NVIDIA GPU sFlow NVML โœ…

Serialization / Deserialization Support

Enables optional serialization and deserialization support for all sFlow data structures using serde. This allows you to easily convert parsed sFlow data to and from JSON, YAML, or any other format supported by serde.

[dependencies]
sflow-parser = { version = "0.3", features = ["serde"] }
serde_json = "1.0"

Example usage:

use sflow_parser::parse_datagram;

let datagram = parse_datagram(&data)?;

// Serialize to JSON
let json = serde_json::to_string(&datagram)?;

// Deserialize from JSON
let datagram: SFlowDatagram = serde_json::from_str(&json)?;

Testing

Unit & Integration Tests

Run the comprehensive test suite:

make test              # Run all tests
make test-unit         # Run unit tests only
make test-integration  # Run integration tests only

Fuzz Tests

The project includes comprehensive fuzz testing using cargo-fuzz:

make fuzz-install     # Install fuzzing tools (requires nightly Rust)
make fuzz-single      # Fuzz single datagram parsing (60s)
make fuzz-multiple    # Fuzz multiple datagrams parsing (60s)
make fuzz-structured  # Fuzz with structured inputs (60s)
make fuzz-all         # Run all fuzzers (5 minutes each)

Specifications Validation

The project includes comprehensive validation against official sFlow specification documents using syn crate to parse Rust source files and extract sFlow struct metadata:

make specs-validate

This validation allowed us to identify additional specification issues that are not yet part of the official errata.

Benchmarks

Performance benchmarks using Criterion:

make bench

Results: ~150ns per datagram (~750.45 MiB/s throughput) on typical hardware. The parser is not zero-copy (at least for now) and does not use any unsafe code, but it is fast enough for most use cases.

License

This project is licensed under the MIT License.

sFlowยฎ is a registered trademark of InMon Corp. This implementation is based on the sFlow version 5 specification available at https://sflow.org/sflow_version_5.txt and is licensed under the terms provided at https://inmon.com/technology/sflowlicense.txt.

Releases

Sponsor this project

Packages

Contributors

Languages