Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Receive and query IPFIX and NetFlow flow records from network devices via UDP.
.claude/skills/automateyournetwork-ipfix-receiver/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-04 | ✗→✓ | ▲ Improved | -36% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -15% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 17% | 0% |
| case-17 | ✗→✓ | ▲ Improved | -6% | 0% |
| case-08 | ✗→✓ | ▲ Improved | -54% | 0% |
Receive and query IPFIX and NetFlow flow records from network devices via UDP.
ipfix-receiver
This skill enables NetClaw to receive IPFIX (RFC 7011) and NetFlow (v5/v9) flow records from network devices and query the collected data. It provides visibility into network traffic patterns, bandwidth usage, and communication flows.
ipfix-mcp
| Tool | Purpose | |------|---------| | ipfix_start_receiver | Start listening for flow exports | | ipfix_stop_receiver | Stop the receiver | | ipfix_get_status | Check receiver status and statistics | | ipfix_query_flows | Search flows with filters | | ipfix_get_flow | Get full details of a specific flow | | ipfix_top_talkers | Identify highest bandwidth consumers | | ipfix_get_templates | List cached flow templates |
1. Use ipfix_start_receiver with port 2055
2. Configure network devices to export flows to this port
3. Use ipfix_get_status to verify flows are being received1. Use ipfix_top_talkers to see highest traffic sources/destinations
2. Filter by time range if investigating specific period
3. Use ipfix_query_flows with src_ip to drill into specific host1. Use ipfix_query_flows with src_ip or dst_ip filter
2. Add protocol filter (6=TCP, 17=UDP) for specific traffic
3. Use min_bytes filter to focus on significant flows1. Use ipfix_top_talkers to see protocol breakdown
2. Query specific protocols with ipfix_query_flows
3. Analyze port usage patternsThe ipfix-mcp server is configured via environment variables:
IPFIX_PORT: UDP listening port (default: 2055)IPFIX_BIND_ADDRESS: Bind address (default: 0.0.0.0)IPFIX_RETENTION_HOURS: Flow retention (default: 24)IPFIX_RATE_LIMIT: Max flows/second (default: 10000)IPFIX_DEDUP_WINDOW: Dedup window in seconds (default: 5)syslog-receiver - Syslog message collectionsnmptrap-receiver - SNMP trap collectiongnmi-telemetry - Streaming telemetryOther measured skills in the registry, with their headline benchmark lift.