08-27-2015 01:23 AM
Yesterday we noticed a short ingress packet burst (jump from 10-15kpps to 180kpps) on two 1GE interfaces of a XMR4000 system running 5.6.0f. Our SNMP check system (MRTG, CACTI) recognized the increased packet and byte count but we saw nothing in the sFlowTrend v6.0 tool.
The packet burst was most likely destinated to an not existing IP address and hence Null-routed and droped on this system (ip route 0.0.0.0/0 null0 -> drop), because we saw no egress packet burst.
My question is now if such (hardware?) droped packets could be observed by S-Flow or not.
Thx for any hints and thoughts in advance!