Sponsored Content
Operating Systems Solaris How to read the output of snoop command? Post 302823935 by fretagi on Thursday 20th of June 2013 03:59:10 AM
Old 06-20-2013
How to read the output of snoop command?

Hi!

I have run the following command:
Code:
snoop -q -d e1000g0 -o /var/tmp/optima0.txt &

them I am trying to read the output of it with
Code:
snoop -i /var/tmp/optima0.txt

, which is giving me this:
Code:
 # snoop -i /var/tmp/optima0.txt | more
  1   0.00000     AIOPTSVR -> 10.100.4.72  TCP D=1393 S=22 Push Ack=3687196293 Seq=1076546811 Len=68 Win=49680
  2   0.00058  10.100.4.72 -> AIOPTSVR     TCP D=22 S=1393 Ack=1076546879 Seq=3687196293 Len=0 Win=257
  3   0.00549            ? -> *            ETHER Type=9C9D (Unknown), size = 62 bytes
  4   0.00001  190.54.1.61 -> AIOPTSVR     NFS C 4 (lookup      ) PUTFH FH=7EEE SAVEFH LOOKUP opx_LOD_GEN_110_00311002O.tmp GETFH GETATTR 1001
1a b0a23a RESTOREFH N...
  5   0.00022     AIOPTSVR -> 190.54.1.61  NFS R 4 (lookup      ) NFS4ERR_NOENT PUTFH NFS4_OK SAVEFH NFS4_OK LOOKUP NFS4ERR_NOENT
  6   0.00043  190.54.1.61 -> AIOPTSVR     NFS C 4 (lookup      ) PUTFH FH=7EEE SAVEFH LOOKUP opx_LOD_GEN_110_00311002P.tmp GETFH GETATTR 1001
1a b0a23a RESTOREFH N...
  7   0.00010     AIOPTSVR -> 190.54.1.61  NFS R 4 (lookup      ) NFS4ERR_NOENT PUTFH NFS4_OK SAVEFH NFS4_OK LOOKUP NFS4ERR_NOENT
  8   0.00032  190.54.1.61 -> AIOPTSVR     TCP D=2049 S=1012 Ack=2632316802 Seq=1922933243 Len=0 Win=49640
  9   0.00309  190.54.1.61 -> AIOPTSVR     NFS C 4 (lookup      ) PUTFH FH=7EEE SAVEFH LOOKUP opx_LOD_GEN_110_00311002K.tmp GETFH GETATTR 1001
1a b0a23a RESTOREFH N...

and
Code:
# snoop -i /var/tmp/optima0.txt | tail
2949   0.12226  10.100.4.72 -> AIOPTSVR     TCP D=22 S=1393 Push Ack=1076548579 Seq=3687197645 Len=52 Win=257
2950   0.00066     AIOPTSVR -> 10.100.4.72  TCP D=1393 S=22 Push Ack=3687197697 Seq=1076548579 Len=52 Win=49680
2951   0.00010     AIOPTSVR -> 10.100.4.72  TCP D=1393 S=22 Push Ack=3687197697 Seq=1076548631 Len=52 Win=49680
2952   0.00009     AIOPTSVR -> 10.100.4.72  TCP D=1393 S=22 Push Ack=3687197697 Seq=1076548683 Len=52 Win=49680
2953   0.00067  10.100.4.72 -> AIOPTSVR     TCP D=22 S=1393 Ack=1076548735 Seq=3687197697 Len=0 Win=256
2954   0.01265            ? -> *            ETHER Type=9C9D (Unknown), size = 62 bytes
2955   0.02180            ? -> *            ETHER Type=9C9D (Unknown), size = 62 bytes
2956   0.00066            ? -> (multicast)  ETHER Type=060F (Unknown), size = 529 bytes
2957   0.01732            ? -> *            ETHER Type=9C9D (Unknown), size = 62 bytes
2958   0.01994            ? -> *            ETHER Type=9C9D (Unknown), size = 62 bytes
root@AIOPTSVR #

But I m not able to interpret this. Please can you help?
 

10 More Discussions You Might Find Interesting

1. UNIX for Advanced & Expert Users

Read the entire output fired by ps command

Actually I want to display the entire output fired by ps command. My output gets trucated after 80 chars. Thus, i am not able to see the entire command running when i give a ps -eaf .... Does anyone know how do i display the entire output fired by ps command .. (i.e the command along with... (5 Replies)
Discussion started by: vinithepoo
5 Replies

2. Solaris

snoop command

Hi. I'm trying to capture traffic with the snoop command using the net expression but I fail when a I've to specify a subnet ex: 10.201.64/18 Did you know the correct syntax? I've tried with snoop -ta -x0 net 10.201.64.0 255.255.192.0 but doesn't match. Thnx (4 Replies)
Discussion started by: kurtolo
4 Replies

3. Programming

How to read output of a shell command

Hello All, I have a an application written in C and runing on Red Hat Linux. In my code I have written a command that is fired on the linux shell by using system() function call. Now I need to read the output of this command in my c program and assign it to a variable. Can anyone... (1 Reply)
Discussion started by: shamik
1 Replies

4. Shell Programming and Scripting

Script to capture snoop output

Hi Everyone :), Need your advice as I'm new to UNIX scripting.. I'm trying to write a script to capture snoop output for 5 minutes for every hour for 24 hours. To stop snoop, I need to press Control-C to break it. This is what I got so far, but now I'm stuck! :confused: The script: # cat... (2 Replies)
Discussion started by: faraaris
2 Replies

5. Shell Programming and Scripting

how to read tail -F command output in perl

Hi All, How I will read the output of the tail -F command in perl. I have text file with below contains file1.txt 1 2 3 4 $running=1; sub openLog($) { (my $log) = @_; (1 Reply)
Discussion started by: pravin27
1 Replies

6. Shell Programming and Scripting

Parse snoop output

Hi all, Is it possible to create an script that parse an snoop output similar to the example above ? Each line is ended by "$" (set list in vi). as a result, I would like to print the output in only one line. can someone give me some tip ? Thanks a lot .:) l version="1.0" ... (5 Replies)
Discussion started by: robdcb
5 Replies

7. UNIX for Dummies Questions & Answers

read command - using output from command substitution

Hey, guys! Trying to research this is such a pain since the read command itself is a common word. Try searching "unix OR linux read command examples" or using the command substitution keyword. :eek: So, I wanted to use a command statement similar to the following. This is kinda taken... (2 Replies)
Discussion started by: ProGrammar
2 Replies

8. Shell Programming and Scripting

read line and run a different command according to the output

Hi. I'm trying to write a script that reads a line on a file and runs a different command for a different line output. For example, if it finds the word "Kuku" on the line it sends mail to Kuku@kuku.com. Otherwise, it sends mail to Lulu@lulu.com. TIA. (2 Replies)
Discussion started by: Doojek9
2 Replies

9. UNIX for Advanced & Expert Users

ls output into a read command as a variable

I'm working on a short BASH script on my Ubuntu box that will run powerpoint scripts with MS Powerpoint Viewer 2007 via WINE. I can run the presentation when I run it manually but what i'd like to do is have the script look for the newest file then run it. #! /bin/sh # Start the newest... (2 Replies)
Discussion started by: binary-ninja
2 Replies

10. Shell Programming and Scripting

Read several variables from command output via SSH

Hi Folks, I'm currently trying to read several values into different variables. Actually, what I'm doing works, but I get an error message. My attempts are: read strCPROC strIPROC strAPROC <<<$(ssh -n -T hscroot@$HMC "lshwres -r proc -m $strIDENT --level sys -F \"configurable_sys_proc_units... (11 Replies)
Discussion started by: NKaede
11 Replies
newproc.d(1m)							   USER COMMANDS						     newproc.d(1m)

NAME
newproc.d - snoop new processes. Uses DTrace. SYNOPSIS
newproc.d DESCRIPTION
newproc.d is a DTrace OneLiner to snoop new processes as they are run. The argument listing is printed. This is useful to identify short lived processes that are usually difficult to spot using traditional tools. Docs/oneliners.txt and Docs/Examples/oneliners_examples.txt in the DTraceToolkit contain this as a oneliner that can be cut-n-paste to run. Since this uses DTrace, only users with root privileges can run this command. EXAMPLES
This prints new processes until Ctrl-C is hit. # newproc.d FIELDS
CPU The CPU that recieved the event ID A DTrace probe ID for the event FUNCTION:NAME The DTrace probe name for the event remaining fields These contains the argument listing for the new process DOCUMENTATION
See the DTraceToolkit for further documentation under the Docs directory. The DTraceToolkit docs may include full worked examples with ver- bose descriptions explaining the output. EXIT
newproc.d will run forever until Ctrl-C is hit. AUTHOR
Brendan Gregg [Sydney, Australia] SEE ALSO
execsnoop(1M), dtrace(1M), truss(1) version 1.00 May 15, 2005 newproc.d(1m)
All times are GMT -4. The time now is 03:17 PM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy