用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/automateyournetwork/netclaw --skill ipfix-receiver命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | ipfix-receiver |
| description | Receive and query IPFIX and NetFlow flow records from network devices via UDP. |
| version | 1.0.0 |
| license | Apache-2.0 |
| author | netclaw |
| tags | [] |
Receive and query IPFIX and NetFlow flow records from network devices via UDP.
ipfix-receiver
This skill enables NetClaw to receive IPFIX (RFC 7011) and NetFlow (v5/v9) flow records from network devices and query the collected data. It provides visibility into network traffic patterns, bandwidth usage, and communication flows.
ipfix-mcp
| Tool | Purpose |
|---|---|
ipfix_start_receiver | Start listening for flow exports |
ipfix_stop_receiver | Stop the receiver |
ipfix_get_status | Check receiver status and statistics |
ipfix_query_flows | Search flows with filters |
ipfix_get_flow | Get full details of a specific flow |
ipfix_top_talkers | Identify highest bandwidth consumers |
ipfix_get_templates | List cached flow templates |
1. Use ipfix_start_receiver with port 2055
2. Configure network devices to export flows to this port
3. Use ipfix_get_status to verify flows are being received
1. Use ipfix_top_talkers to see highest traffic sources/destinations
2. Filter by time range if investigating specific period
3. Use ipfix_query_flows with src_ip to drill into specific host
1. Use ipfix_query_flows with src_ip or dst_ip filter
2. Add protocol filter (6=TCP, 17=UDP) for specific traffic
3. Use min_bytes filter to focus on significant flows
1. Use ipfix_top_talkers to see protocol breakdown
2. Query specific protocols with ipfix_query_flows
3. Analyze port usage patterns
The ipfix-mcp server is configured via environment variables:
IPFIX_PORT: UDP listening port (default: 2055)IPFIX_BIND_ADDRESS: Bind address (default: 0.0.0.0)IPFIX_RETENTION_HOURS: Flow retention (default: 24)IPFIX_RATE_LIMIT: Max flows/second (default: 10000)IPFIX_DEDUP_WINDOW: Dedup window in seconds (default: 5)syslog-receiver - Syslog message collectionsnmptrap-receiver - SNMP trap collectiongnmi-telemetry - Streaming telemetry