2013-12-05_tcpflow-and-BE-update
2013-12-05_tcpflow-and-BE-update
2013-12-05_tcpflow-and-BE-update
- No tags were found...
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
tags generated by <strong>tcpflow</strong> match fiwalk’s.Note:031.013.069.160.00443-010.002.107.009.5213376a1e0610d76af60000e8a0710a6bb59c6• Processing flows with XML is non-st<strong>and</strong>ard but relatively easy.• 10-20GB DFXML files can be rapidly processed with dfxml.py (SAX-based parser).Other output options in development:• sqlite• Netflow? RFC5665 IPFIX? SiLK? FlowCollector?11