07-08-2006
enhanced tcpdump is needed
Are there any standard programs in linux/unix like tcpdump that store packets' headers in db (Berkeley DB is preffered, including secondary db's to index stored headers by IP addesses, TCP flows, etc.), provide search in db and convert found headers to tcpdump dumpfile format?
7 More Discussions You Might Find Interesting
1. UNIX for Advanced & Expert Users
We are using c2 / enhanced security on digital unix.
I do not have access to the GUI.
I need to get information on login status for users. Specifically I would like to know who has not logged in within the last 6 months.
I think I can query the edauth files, but I can't find information on... (4 Replies)
Discussion started by: MizzGail
4 Replies
2. Solaris
Hello;
I am moving a customer from Solaris 2.6 to Solaris 2.8. The customer has requested the following two requirements also be implemented:
1. Lock a user account out for X number of days after 3 unsuccessful login attempts.
2. No reuse of the last 5-10 passwords. Also referred to... (1 Reply)
Discussion started by: rambo15
1 Replies
3. UNIX for Advanced & Expert Users
for sco, hp, or AIX......
anyway, how can I secure the UNIX system.
I knew that CA has it's products for securing the UNIX server system.
Please tell me more about other vender, and their products
thxs! (0 Replies)
Discussion started by: brookwk
0 Replies
4. Shell Programming and Scripting
Dear
I have a problem on which I turn araound since hours.
Hope you could help me.
I have a bash script, which activates with "nohup ./script2 params & " several subscripts.
In my main script, I have set lot's of variables, which I would pass into script 2.
My idea is now to create a... (3 Replies)
Discussion started by: pramach
3 Replies
5. UNIX for Dummies Questions & Answers
Hi. I guess this my dummy question is for super-gurus.
I'm on Red Hat' documentation regarding their RDMA capabilities over "convergent" Ethernet network. I read everything that I could find on inet, wikipedia etc. about the technology itself. I can't figure out, how can I determine if the... (0 Replies)
Discussion started by: newlinuxuser1
0 Replies
6. AIX
Hi All,
I am going to perform some activity in 2Node HA Server(Active/Passive).
For that i have to do some pre-requsite (ie., Resource Group VG's should be Enhanced-Concurrent)
In my setup, we have two volume groups in one RG. In that one VG is Normal and another is Enhance Concurrent.
... (2 Replies)
Discussion started by: Thala
2 Replies
7. What is on Your Mind?
Dear All,
Thank you for your support. As promised I have upgrade features for unix.com forum VIP members as follows:
Who's Online Permissions
Can View IP Addresses
Can View Detailed Location Info for Users
Can View Detailed Location Info of Users Who Visit Bad / No Permission... (0 Replies)
Discussion started by: Neo
0 Replies
ttt(1) net ttt(1)
NAME
ttt - Tele Traffic Tapper - a standalone program for local, real-time, graphical traffic-monitoring.
SYNTAX
ttt [-interface device] [-interval ms] [-dumpfile file [-speed N]] [-yscale (K|M|n)]
DESCRIPTION
ttt is the standalone traffic monitor program in the ttt program suite. It displays trafic-data of a local interface.
To run ttt, you must be "root" on most systems since only root is allowed to access the network filter device.
The ttt program suite is yet another descendant of tcpdump but it is capable of real-time, graphical, local and remote traffic-monitoring.
It won't replace tcpdump, rather, it helps you find out what to look into with tcpdump.
OPTIONS
-interface device
specifies the interface for packet capture. If not specified, the default interface is chosen.
-interval ms
Sets the interval in Milliseconds. If omitted, a interval of 1000 msec. is used as default.
-dumpfile file [-speed N]
use a dumpfile (produced by "tcpdump -w") as input. The speed option specifies the acceleration factor of the replay speed.
-yscale ('K'|'M'|n)
change the scale of y-axis. 'K' and 'M' represent 1000 and 1000000 respectively.
EXAMPLES
To run this program the standard way type:
ttt
To listen only on interface eth0:
ttt -interface eth0
AUTHORS
ttt was written by Kenjiro Cho < kjc@csl.sony.co.jp>.
This manual page was written by Thomas Scheffczyk <thomas.scheffczyk@verwaltung.uni-mainz.de>, for the Debian GNU/Linux system (but may be
used by others).
SEE ALSO
tttview(1), tttprobe(1)
Kenjiro Cho 1.7 ttt(1)