{{indexmenu_n>5}}
====== Configuring Export and Template of DPI Traffic Processing Events in IPFIX Format ======
DPI traffic processing events (for example, triggering of CG-NAT limits) are exported via a dedicated IPFIX channel — ''ipfix_reporting''.
===== Export Configuration =====
Event export is configured with the following parameters:
ipfix_reporting_udp_collectors=1.2.3.4:1500
ipfix_reporting_tcp_collectors=1.2.3.6:9418
reporting_events=2
reporting_events_min_queue=512
reporting_events_rate_limit=100/s
where
* **''ipfix_reporting_udp_collectors''** — addresses of UDP collectors.
* **''ipfix_reporting_tcp_collectors''** — addresses of TCP collectors.
* **''reporting_events''** — bit mask of the event types to be exported. Default is 0 (the subsystem is disabled and no memory is allocated for events). The bit number corresponds to the event type:
* ''2'' — CG-NAT session limit triggered\\ Example: ''reporting_events=2''
* **''reporting_events_min_queue''** — capacity of the worker thread's event queue, in messages. The actual capacity is at least the specified value: the buffer size is rounded up to a power of two. Default is 512.
* **''reporting_events_rate_limit''** — event export rate limit in the format ''[/[]]''; the default period is one second. Default is 0 (no limit). Example values: ''100'', ''100/s'', ''10/100ms'', ''50/2s''.
===== IPFIX Template =====
The IPFIX record structure is defined by the ''reporting_ipv4'' and ''reporting_ipv6'' templates.
**Standard IANA fields:**
^ ID ^ Name ^ Description ^
| 323 | observationTimeMilliseconds | Event time |
| 8 / 27 | source**IPv4**Address / source**IPv6**Address | Source address |
| 12 / 28 | destination**IPv4**Address / destination**IPv6**Address | Destination address |
| 7 | sourceTransportPort | Source port |
| 11 | destinationTransportPort | Destination port |
| 4 | protocolIdentifier | Protocol identifier |
| 56 | sourceMacAddress | Source MAC address |
| 80 | destinationMacAddress | Destination MAC address |
| 58 | vlanId | Inner VLAN |
| 243 | dot1qVlanId | Outer VLAN (QinQ) |
**Enterprise fields (PEN 43823):**
^ ID ^ Name ^ Description ^
| 3300 | event_type | Event type |
| 3301 | event_count | Total number of events of this type since startup |
| 3302 | sample_rate | Number of events suppressed by the rate limiter since the previous record |
Event types with the same set of fields share a common template and are distinguished by the ''event_type'' field. Separate templates will be added for event types that have their own set of fields.