# pmacct/pmacct

pmacct is a small set of multi-purpose passive network monitoring tools [NetFlow IPFIX sFlow libpcap BGP BMP RPKI IGP Streaming Telemetry].

Repository: https://github.com/pmacct/pmacct
Canonical: https://ross.abutalabs.com/products/pmacct
Homepage: http://www.pmacct.net
Language: C
License: NOASSERTION
License Family: other
Topics: netflow, ipfix, sflow, bgp, bmp, kafka, rabbitmq, libpcap, nflog, geoip2, ndpi, mysql, postgresql, sqlite3, sql, json, avro, rpki, pmacct, bgp-ls
Last push: 2026-08-24T14:18:17+00:00

## Health v2 (maintenance only)
Score: 67/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 8, longevity 100
- inputs: {"age_days": 3916, "days_push": 9, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1237, forks 283 (observed 2026-08-28T04:04:05.362385+00:00)

## What it is
pmacct is a set of multi-purpose passive network monitoring daemons written in C that collect, aggregate, replicate and export IP traffic accounting data via libpcap, NetFlow, IPFIX, sFlow, NFLOG, plus control-plane data from BGP, BMP, RPKI, IGP and Streaming Telemetry. It stores results in SQL/noSQL databases, Kafka, RabbitMQ, memory tables or flat files, and can enrich flow data with BGP correlation.

## Use cases
- collect and account NetFlow and IPFIX flows from routers
- capture sFlow samples from switches
- correlate NetFlow data with BGP information
- store traffic accounting data in MySQL or PostgreSQL
- export flows to Kafka or RabbitMQ for downstream analytics
- monitor BGP peers and dump routing tables
- collect streaming telemetry from network devices
- replicate flow exports to multiple collectors

## When to choose
- you need ISP/IXP/CDN-grade passive traffic accounting and flow collection
- you want to correlate data-plane flows with BGP/BMP control-plane data
- you need flexible export to databases, Kafka, AMQP or flat files
- you run Linux/BSD servers or embedded network appliances

## When to avoid
- you need a GUI dashboard or turnkey network monitoring suite like Nagios or Zabbix
- you only need simple packet sniffing without aggregation (use tcpdump or Wireshark)
- you want active probing or synthetic traffic monitoring

## Facets
- artifact type: application
- maturity: active
- function: monitoring, analytics, streaming, search-engine
- domain: networking, monitoring, security, big-data
- platform: bsd, cli, self-hosted
- tags: netflow, ipfix, sflow, bgp, bmp, rpki, streaming-telemetry, traffic-accounting, network-monitoring, kafka, libpcap, linux, docker

## Member repositories
- pmacct/pmacct (main) score 67

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:05.362385+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T08:21:53.966537+00:00, confidence not recorded.
  - readme: https://github.com/pmacct/pmacct (fetched 2026-08-28T04:04:05.362385+00:00, sha 5207b07a41b5)
  - homepage: http://www.pmacct.net (fetched 2026-08-29T12:21:08.763705+00:00, sha 8c4ce4c036d1)
  - site_page: http://www.pmacct.net/docs/cacti.html (fetched 2026-08-29T12:21:08.782804+00:00, sha 22bc70eb15f2)
  - site_page: http://www.pmacct.net/ChangeLog-1.7.9 (fetched 2026-08-29T12:21:08.772999+00:00, sha 9dd555fa3e66)
  - site_page: http://www.pmacct.net/FAQS-1.7.9 (fetched 2026-08-29T12:21:08.780621+00:00, sha f54bb2934219)
- Data as of 2026-08-30T08:39:29.467469+00:00.
