Repository navigation
Conversation
Register `netflow` as an aggregator source type and create its Service port as UDP. - aggregatorTypes: a pipeline whose source is `netflow` gets the aggregator role instead of failing with "unsupported source type: netflow". - extractProtocol: the protocol of the Service port was taken from the `mode` option of the source, which only some sources have. `netflow` listens on UDP and has no such option, so its port was published as TCP. Sources listed in udpOnlyTypes are UDP regardless of their options. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
netflowto the source types the operator knows, and publishes its Service port as UDP.Two things are wrong today for a pipeline that uses a
netflowsource:netflowis on neitheraggregatorTypesnoragentTypes, so the pipeline is marked invalid withunsupported source type: netflow.modeoption (extractProtocol).netflowis UDP-only andhas no
mode, so even with the role pinned the port would be published as TCP.The change:
NetflowTypeis added toaggregatorTypes(a network listener, it belongs on an aggregator).udpOnlyTypesset lists the sources that are UDP regardless of their options, andextractProtocolnow takes thesource type as well as its options. Behaviour for every other type is unchanged (
mode: udpstill selects UDP).Note on the source itself
The
netflowsource is not in a released Vector yet: it is the open PR vectordotdev/vector#24628 (NetFlow v5 over UDP,the first of a planned series). This change only registers the type, so that the operator does not reject the config once
a Vector that has the source is used. I understand if you would rather wait until the source is released; I have been
running this together with a Vector build that includes that PR.
It is complementary to #283:
spec.rolelets a pipeline with an unlisted source type through, but the Service port of aUDP-only source still needs to be UDP, which is what
udpOnlyTypesis for.How did you test this PR?
internal/config/netflow_source_test.go:extractProtocolfornetflow,syslogwithmode: udp/tcpand
vector;VectorRole()of anetflowpipeline isaggregator.go test ./internal/config/...passes.VectorAggregatorwith anetflowpipeline (two sources on UDP 2055 and 2056) became valid, theoperator created a Service with
2055/UDP,2056/UDP, and flow records sent to those ports reached the sink.🤖 Generated with Claude Code