Re: [logs] Tcpdump log analysis

From: Yann Berthier (yb@sainte-barbe.org)
Date: Thu Feb 20 2003 - 07:23:40 PST

  • Next message: Bennett Todd: "Re: [logs] state machines and (automated) log analysis -- any tools?"

    On Thu, 20 Feb 2003, Fabien Pouget wrote:
    
    > 
    > 
    > Hi all,
    > 
    > I collected many binary logs with tcpdump. I would like to study them
    > and to do so, I planned to export these files into a mysql database. 
    > What I am doing now is simply to collect few data through perl scripts
    > and analyze them. But no database... 
    > Does it exist any tools to help me fulfil this task ? Or any trick I
    > missed ?
    > 
    > 
    > Any help would be very appreciated
    
       Perhaps this is a bit off topic for this list, but anyway: i'm not
       sure what you are trying to achieve with these dumps, and why do you
       think you need a database, but you could consider a tool like argus
       (http://qosient.com/argus/) to help you analyse these dumps by
       studying network flows, and aggregating them as needed. A tool like
       this is especially usefull when you need to parse big pcap dumps.
    
       But of course it depends a lot of what you want to spot in your
       traces.
    
       Contact me off list if you need more info
    
          - yann
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Thu Feb 20 2003 - 07:31:08 PST