Version 75 (modified by andreu, 10 years ago)


renetcol home page

renetcol ( RENATER  NetFlow Collector) is a NetFlow collector under GPL. NetFlow is a technology originally proposed by  Cisco, that is currently under standardization in  IPFIX IETF working group. renetcol works with NetFlow Data Export version 9, which allows to monitor IPv6, Multicast and MPLS flows, in addition to the IPv4 ones.

The main functionnalities of renetcol are:

  • Real-time NetFlow viewer (if you've ever dreamed of using tcpdump on an IP operator backbone, you should test renetcol)
  • RRD accounting for IPv4 subnet (CIDR)
  • RRD accounting for BGP AS number
  • RRD accounting for IPv6 links (new in release 0.0.14)
  • Inter-POP flows Matrix
  • DoS attack detection

Screenshots and graphic examples

  • Web interface here
  • Class of services traffic distribution for an IPv4 prefix: here
  • Real-time flow monitoring: here
  • Examples of different possibility of flow selection: here
  • IPv6 Weathermap of RENATER backbone (with  YANMP):  here

Next features

  • Flow historic
  • Accounting for IPv6 subnet
  • DDoS detection
  • nfcapd format export


  • New architecture of core: SMP arch, to reached the million of flows per second (fps) on a single hardware.

Online documentation

White Paper



renetcol in production



  • Andreu François-Xavier

Thanks to

  • CERT RENATER (for his daily usage of renetcolGUI)
  • Anthony Fisson (for syslog section and discussions about SMP architecture)