This guide follows Juniper’s documentation and has been tested on a Juniper EX switch. Check every statement against the documentation for your Junos release; lines we haven’t seen verbatim there are marked check on your release.
Heimnull receives sFlow v5 on 6343/udp by default. Each flow sample is one sampled packet: Heimnull reads its header (addresses, ports, protocol, TCP flags, fragments, VLAN), the sampling rate carried in the sample, and the input and output ifIndex. Counter samples are ignored, because interface counters come from SNMP (Exporters → SNMP).
Configuration
set protocols sflow collector 10.0.0.10 udp-port 6343
set protocols sflow agent-id 10.0.0.4
set protocols sflow sample-rate ingress 2048
set protocols sflow polling-interval 0
set protocols sflow interfaces ge-0/0/47.0
set protocols sflow interfaces ge-0/0/46.0
- collector is the Heimnull host. The EX allows up to 4 collectors. The default UDP port is 6343.
- agent-id is a stable address for the switch, so the agent ID isn’t dynamic. Heimnull identifies the exporter by the source address of the UDP datagrams, so keep that address stable too: the switch sends from the interface that routes to the collector. Check on your release whether
source-ipunder[edit protocols sflow]lets you set it. - sample-rate
ingress Nsamples 1 in N packets entering the interface (from 1 to 1,073,741,823). The bare-number form was removed in Junos 10.4 for EX. Setting onlyegressturns ingress sampling off. Interface-level settings override the global ones. - interfaces are the uplinks or customer-facing ports whose traffic Heimnull should see. Not Layer 3 VLAN-tagged interfaces, and not
aebundles: configure the member links. - polling-interval 0 turns counter samples off. Heimnull doesn’t use them.
Pick the sample rate from the traffic
The EX samples at most 300 packets per second per FPC, and Juniper documents that limit as not configurable. Above it, samples are dropped, and every rate Heimnull computes reads low. So pick N from the traffic, not from a default:
| Traffic on the line card | Packets per second (700-byte average) | 1 in N for under 300 samples/s |
|---|---|---|
| 1 Gbit/s | about 180,000 | 1 in 1024 |
| 10 Gbit/s | about 1.8 million | 1 in 8192 (about 220 samples/s) |
Use the same rate on every port of a line card, as Juniper recommends. Heimnull reads the rate from every sample, so there’s nothing to set on its side.
Which direction to sample
Sample one direction per link, at the edge: ingress on uplinks sees traffic entering your network, and ingress on the switch’s other ports sees the reverse. Sampling both ingress and egress on the same path counts each packet twice.
In Heimnull
- The switch appears under Exporters when its first datagram arrives, or waits for approval if auto-accept is off.
- Inbound and outbound come from Networks (your prefixes), as for every exporter. Give the switch’s interfaces roles under Interfaces (the uplink as Transit) to classify traffic the prefixes alone can’t. ifIndex values come from the samples, and SNMP names them.
- The sampling rate shows as detected on the exporter’s page.
sFlow samples are packet samples, like a Juniper MX’s IPFIX inline monitoring: they arrive within a second or two, so the Live page shows per-second detail and detection reacts in about 5.5 seconds.
Check it
On the switch (check the commands on your release):
show sflow: sampling rates, polling interval and agent IDshow sflow interface: per-interface ratesshow sflow collector: samples sent to each collector
In Heimnull, the exporter’s page under System shows datagrams, records and packet samples, and Live can be filtered by the exporter.
Sources: Juniper, “Example: Configure sFlow Technology to Monitor Network Traffic” (EX Series), the sample-rate and agent-id statement references, and “Configuring sFlow Technology for Network Monitoring (CLI Procedure)”.