![]() |
|
|
|
|
|||||||
| Forums | Portal | Register | Rules & FAQ | Contribute | Members List | Arcade | Search | Today's Posts | Mark Forums Read |
| IP Networking Questions involving TCP/IP, Routers, Hubs, Network protocols, etc go here. |
|
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| tcpdump on AIX | nymus7 | AIX | 4 | 01-16-2008 04:51 PM |
| R-326: tcpdump | iBot | Security Advisories (RSS) | 0 | 01-08-2008 08:50 AM |
| Tcpdump in cron | paulzeromi | Shell Programming and Scripting | 5 | 07-22-2007 07:24 PM |
| tcpdump | ant04 | UNIX for Dummies Questions & Answers | 2 | 09-07-2004 03:36 PM |
| How To Use tcpdump | chenhao_no1 | High Level Programming | 2 | 04-01-2003 05:15 AM |
|
|
LinkBack | Thread Tools | Display Modes |
|
|||
|
tcpdump question
Hi, I got the following question regarding tcpdump and I would appreciate your help/feedback:
--Scenario I am instructed to capture the network traffic by getting the tcpdump data/files of our network for every hour. --Problem Some of the connections are still open when the capture is done at the end of 30 minutes. How do I link these open connections in different tcpdump files? --example Connection A: 192.168.10.1:1686 --> 192.168.10.22:139 connection A starts: 12:25 connection A ends: 12:45 Data capture: 12:00-12:30 (file1), 12:30-1:00 (file2) Will there be two connections (for connection A) -- one in file1, the other in file2? Will their connection start time be the SAME or DIFFERENT? Please help!! Thanks!! Jay |
| Forum Sponsor | ||
|
|