One Unified Global Perspective
Communications with a Global Perspective
Home
Intro
Contact Us
Voice over IP
PBX Solutions
Services
Support
Glossary
Open Source
Blog
Forum

WebMail





2007 Mar 02 - Fri

Darvas Results at EOD 2007/03/02 with EOD Signal of 2007/03/01

In comparison, the Dow Jones Industrial Index opened at 12233, had a lower high of 12247, had a higher low of 12107, and closed down for the day at 12114.

Symbol#OpenHighLowCloseStopO->HO->C
ABT153.5353.6552.5853.0154.280.12-0.52
ADI236.1536.3735.1835.3536.640.22-0.80
ADP149.7649.7648.6848.6850.330.00-1.08
AEP145.3845.5944.8544.8745.370.21-0.51
AKS122.9023.2021.3021.7922.030.30-1.11
ALTR220.4820.6820.2120.2621.480.20-0.22
AMCC13.713.773.573.633.680.06-0.08
AMKR111.7211.8311.3111.3212.040.11-0.40
ATHR124.7925.2024.0824.3126.710.41-0.48
ATI2100.00101.4895.9597.06104.511.48-2.94
AUY213.8414.1013.3913.7715.250.26-0.07
AXL224.3024.3223.6423.6525.820.02-0.65
BBBY139.7540.1839.5039.5542.540.43-0.20
BBI16.776.866.506.526.910.09-0.25
BDN135.0135.1634.5634.5634.020.15-0.45
BG179.6079.6076.8176.9784.030.00-2.63
BNI178.4878.9877.4077.5384.570.50-0.95
CA125.8625.8625.4725.4925.450.00-0.37
CECO129.7931.8529.7930.2529.852.060.46
CEG179.0979.0977.7977.8177.420.00-1.28
CERN352.0052.0750.6750.6753.280.07-1.33
CF237.6038.4336.2036.5638.110.83-1.04
CHL145.4346.2744.8745.0049.570.84-0.43
CMS117.3517.3617.0417.0717.020.01-0.28
CNP217.1517.6317.0317.5018.310.480.35
CTSH188.4588.9386.9286.9391.000.48-1.52
D185.4585.6885.0085.0084.700.23-0.45
DD250.7950.9549.8350.0952.950.16-0.70
ED348.6048.6348.0648.0849.250.03-0.52
EQ254.8955.0653.3453.3957.050.17-1.50
ESLR19.749.909.359.4110.680.16-0.33
FAF147.2248.2746.9647.8246.701.050.60
FE162.5062.5961.6561.6564.350.09-0.85
GILD270.3571.5069.7670.4473.251.150.09
GS1198.20200.92195.59195.67219.262.72-2.53
GT126.1627.8826.0327.1925.851.721.03
HES252.9753.2951.1151.4255.060.32-1.55
HL27.787.937.507.568.400.15-0.22
HLT134.1535.4634.1534.6935.841.310.54
HLTH114.7214.8114.5714.6015.480.09-0.12
IR343.0843.3542.4342.6144.000.27-0.47
JBHT126.3026.4025.8025.8127.480.10-0.49
JOYG243.2543.3642.4042.4052.940.11-0.85
KLAC250.5051.1649.5149.9153.650.66-0.59
LLTC232.8132.9432.0832.0833.640.13-0.73
LM1101.88103.1299.4399.43109.031.24-2.45
LWSN17.677.887.677.758.440.210.08
LYO131.8432.0030.7031.0532.480.16-0.79
MET162.9563.1262.1762.4865.790.17-0.47
MHS168.1668.4766.6366.6367.570.31-1.53
NBL357.0357.7856.8957.3857.060.750.35
NIHD169.9970.4869.1569.3170.540.49-0.68
NRG367.1868.4067.1267.4265.791.220.24
NSM125.2025.4724.7724.9625.580.27-0.24
NTES220.0720.4819.7619.9120.600.41-0.16
NVTL213.1213.4413.1013.3312.800.320.21
NYB216.9416.9916.7516.7717.350.05-0.17
OMC1103.33103.90102.62103.12100.610.57-0.21
OMX150.9051.0049.9850.2451.850.10-0.66
ONNN39.689.879.419.4910.460.19-0.19
PAAS327.5428.4826.7526.9731.520.94-0.57
PAYX239.6439.7039.1339.1641.930.06-0.48
PD3124.01124.80123.05123.05124.400.79-0.96
PENN245.5046.1345.3445.6642.950.630.16
PMTC118.8819.0118.4918.6020.180.13-0.28
POT1152.50155.45147.93148.28161.002.95-4.22
PPL238.3338.4537.8537.8538.170.12-0.48
PWR323.3123.4322.3622.3823.310.12-0.93
PX260.9861.3660.4060.5664.200.38-0.42
RIMM1139.94141.31135.96135.97139.741.37-3.97
RIO133.4133.6432.3232.7036.680.23-0.71
RRC332.0032.1131.3031.3131.250.11-0.69
RRI117.2117.4217.1217.1717.060.21-0.04
RYI133.8136.8933.7135.4334.013.081.62
SCUR18.258.458.058.129.350.20-0.13
SHLD1174.89181.15174.89177.10187.276.262.21
SIRF127.9628.5527.5628.0231.700.590.06
SONS17.407.467.147.337.230.06-0.07
STM318.9319.0018.6918.7019.920.07-0.23
STP135.7536.4734.5234.6336.700.72-1.12
SYK161.2861.6560.6761.0063.500.37-0.28
TEVA134.8135.1734.6834.7037.760.36-0.11
TRA116.9817.1016.4316.6517.700.12-0.33
TSM210.9310.9510.6410.6411.300.02-0.29
UIS18.378.438.238.288.920.06-0.09
USG153.4053.7852.7352.8257.740.38-0.58
USU314.2214.3313.8713.9014.980.11-0.32
VSEA147.0847.9546.2446.2947.220.87-0.79
WIN114.8514.8914.3214.3815.100.04-0.47
WYN234.9035.2734.7534.7735.100.37-0.13
XL169.9070.2269.3369.6973.990.32-0.21
XLU238.6438.6438.0538.0539.170.00-0.59
YRCW143.3843.3841.8442.0642.920.00-1.32
933896.9448.45-51.85

[/Trading/Darvas/D200703] permanent link


Installing Netflow Tool: nfsen

nfsen is companion tool to nfdump. Where nfdump handles the capture and writing to disk of netflow records, nfsen takes the captured files and makes the data available through a web interface.

To install, download and expand the latest snapshot (be sure the nfsen snapshot is compatible with the nfdump snapshot):

cd /usr/src
wget http://internap.dl.sourceforge.net/sourceforge/nfsen/nfsen-snapshot-20070208.tar.gz
tar -zxvf nfsen-snapshot-20070208.tar.gz
cd nfsen-snapshot-20070208

To build and install nfsen is a bit more complicated that installing nfdump:

cd etc
cp nfsen-dist.conf nfsen.conf
nano nfsen.conf
* $BASEDIR = "/usr/local/nfsen";
* $CONFDIR = "/etc/nfsen";
* $VARDIR   = "/var/local/nfsen";
* $PROFILESTATDIR="${VARDIR}/profiles";
* $PROFILEDATADIR="/var/local/nfdump/flows";
* $USER    = "www-data";
* $WWWUSER  = "www-data";
* $WWWGROUP = "www-data";
* $SUBDIRLAYOUT = 7;
* %sources = (
*      'bmr01'        => { 'port'    => '9999', 'col' => '#0000ff', 'type' => 'netflow' },
* );
cd ..
./install.pl etc/nfsen.conf


[/OpenSource/Debian/Monitoring] permanent link


Installing Netflow Tool: nfdump

For a while now, I've been using the Flow-Tools set of netflow analysis tools. I've heard that Nfdump and Nfsen are the current netflow tools of choice. The weakness with Flow-tools has been in the web side. The command line tools are rich, but the graphical side has lacked a little. I'm hoping to see something better with this alternate tools set.

Peter Haag, the toolset author, has a presentation titled Watch Those Flows. There is a second, larger paper called Watch your Flows with NfSen and NFDUMP.

Download, expand, and build the snapshot from Sourceforge Nfdump:

cd /usr/src
wget http://internap.dl.sourceforge.net/sourceforge/nfdump/nfdump-snapshot-20070208.tar.gz
tar -zxvf nfdump-snapshot-20070208.tar.gz
cd nfdump-snapshot-20070208
./configure
make 
make install

There are man tools for each of the tools. There must be a separate nfcpad process for each neflow source. So that collection starts on monitoring server boot, these can be placed in the /etc/rc.local config file, which will be processed near the end of the operating system boot process. The author provides the following as an example:

nfcapd -w -D -l /flow_base_dir/router1 -p 23456
nfcapd -w -D -l /flow_base_dir/router2 -p 23457

I've used (pre-create the directory):

nfcapd -p 9999 -l /var/local/nfdump/flows -S 7 -w -I bmr01

Each interface on a Cisco router should have the following:

interface fastethernet 0/0
ip route-cache flow

A basic config to export the flows would be:

ip flow-export  
ip flow-export version 5
ip flow-cache timeout active 5

Note that even though lower end switches like 3550's, 3750's, and 3560's have some of the netflow commands, they will only export process switched flows. Talk to your Cisco account manager, and as a group, we may be able to influence Cisco to provide full netflow capability in 'every day' line of switches.

The alternative to this problem is to use nProbe utility from NTOP. Connect a promiscuous ethernet port to a spanned port on a switch. nProbe will capture the packets, evaluate them, and forward netflows to the netflow capture utility. As a bonus, nProbe is useful in VOIP networks as it knows how to evaluate RTP streams and forward helpful statistics on a per flow basis. I'll try to write this up in another entry.


As a side note, I came across plixer international, who were previouisly known as Somix Technologies. They have a netflow analyzer available for downloading.

[/OpenSource/Debian/Monitoring] permanent link


Installing and Configuing syslog-ng

The syslogging capability that comes standard with Debian gets the job done, but offers little for flexibility. I needed something that would allow simple replication of certain log entries to a vendor's syslog server. BalaBit's syslog-ng is an excellent replacement. And dead easy to install:

apt-get install syslog-ng

This removes the old syslog programs, installs the new ones, and starts things up. The configuration file, although in a different format, attempts to replicate the functionality of the previous programs quite well. The configuration is found in /etc/syslog-ng/syslog-ng.conf. The documentation is straight forward and useful. After taking a quick look at it,the configuration file makes sense, and is easy to add configuration items.

In the configuration file, I added the following to the options section:

use_dns(yes);
use_fqdn(yes);

to add some lookups, even though it may not be recommeded in high volume environments. In the source s_all section, I added:

udp();

in order to allow messages from the Cisco devices. In order forward syslog messages from specific devices to a vendor in order to correlate network problems, I added the following lines:

# external destination for log messages (will require a port opening on firewall)
destination du_externallog { udp("192.2.0.5"); };
# specific device list
filter f_devicesforvendor { host("router1") or host("router2"); };
# perform the logging to vendor
log {
  source(s_all);
  filter(f_devicesforvendor);
  destination(du_externallog);
  }

[/OpenSource/Debian/Monitoring] permanent link



Blog Content ©2008
Ray Burkholder
All Rights Reserved
ray@oneunified.net
(441) 505 7293
Available for Contract Work
Resume

RSS: Click to see the XML version of this web page.

View Ray 
Burkholder's profile on LinkedIn
technorati
Add to Technorati Favorites



March
Su Mo Tu We Th Fr Sa
        2


Main Links:
Monitoring Server
SSH Tools
QuantDeveloper Code

Special Links:
Frink

Blog Links:
Sergey Solyanik
Marc Andreessen
HotGigs
Micro Persuasion
... Reasonable ...
Chris Donnan
BeyondVC
lifehacker
Trader Mike
Ticker Sense
HeadRush
TraderFeed
Stock Bandit
The Daily WTF
Guy Kawaski
J. Brant Arseneau
Steve Pavlina
Matt Cutts
Kevin Scaldeferri
Joel On Software
Quant Recruiter
Blosxom User Group
Wesner Moise
Julian Dunn
Steve Yegge

2007
Months
Mar




Mason HQ

Disclaimer: This site may include market analysis. All ideas, opinions, and/or forecasts, expressed or implied herein, are for informational purposes only and should not be construed as a recommendation to invest, trade, and/or speculate in the markets. Any investments, trades, and/or speculations made in light of the ideas, opinions, and/or forecasts, expressed or implied herein, are committed at your own risk, financial or otherwise.