NetFlow File and Directory Structure
/home/nfcuser — user created to drive NetFlow Analyzer, user working directory
configs — router configs for NFA use (it’s not happy with them)
exports — directory, sym link to directory where NFA drops exported CSV files. Don’t delete!
images — directory to dump screen capture GIF/JPEG saves into
/opt/CSCOnfa — Cisco Flow Data Analyzer
check.All — script to check Java, DisplayServer, UtilityServer are running
start.All — script to start DisplayServer, UtilityServer
stop.All — stops themcisco — mojo (ASN.1/SNMP toolset) — not for user use
NFADisplay — NFA Display UI
bin — programs, scripts, also *.class = Java classes
start.Display script — starts NFA Display screen (UI)
helpRuntimeJava
RuntimeJavaWin95
NFAServer — NFA DisplayServer (Display talks to)
AliasDefn — known AS’s, ports, protocols
[not well documented: see perhaps the UsePortText flag in the NFADS.resources file]
bin — programs, scripts
check.DisplayServer — script to check DisplayServer
DisplayServer — program
NFADS.resources — options for DisplayServer, MaxMB, UsePortText
start.DisplayServer — starts just DisplayServer
stop.DisplayServer — stops it
Cache — cached infoexported_files — where exported CSV files go, /home/nfcuser/exports sym link to this
logs — misc log files (server)
RouterGroup — tree file sets and router groups
util — utilities
mgmt_NFC.exp — expect script (is expect installed?).Appears to copy specified collected info to another directory. Looking at the script, from another machine. Probably used behind the scenes to bring in data from another DisplayServer.
NFAUtility — NFA UtilityServer (does all backend dirty work, talks to NFCGW)
bin — scripts, programs, Java classes
check.UtilityServer
start.UtilityServer
stop.UtilityServer
config — config files for UtilityServer
HostPreferences.txt — address à name translation
NFCCC.txt — NetFlow collectors and userid and port
RouterConfig.txt — address, SNMP community, tms/netflow
Conjecture when NFA looks at directory of router configs, it populates this file. (Not very documented?)
data — AS.txt_0, HostAliases.txt — purpose not clear, probably not user fileslogs — log files for UtilityServer
NFAU.log — log file
state — directory to hold .pid file for UtilityServeroriginals — directory of original config/script files (install probably put locations of things into them)
/opt/CSCOnfc — Cisco FlowCollector