Visualizza - Garr
Visualizza - Garr
Visualizza - Garr
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Scripting+nfdump<br />
•Nfdump prevede un output<br />
machine readable tramite<br />
l’opzione: -o pipe<br />
•Il formato di output è riportato<br />
nella tabella, ogni campo è<br />
separato da un ”pipe”(|).<br />
•Gli indirizzi IP sono<br />
rappresentati da numeri interi.<br />
•L’uso di filtri e<br />
dell’aggregazione non modifica<br />
il formato di output, ma solo il<br />
riempimento dei campi.<br />
Address family<br />
Time first seen<br />
msec first seen<br />
Time last seen<br />
msec last seen<br />
Protocol<br />
Src address<br />
Src port<br />
Dst address<br />
Dst port<br />
Src AS<br />
Dst AS<br />
Input IF<br />
Output IF<br />
TCP Flags<br />
Tos<br />
Packets<br />
Bytes<br />
PF_INET or PF_INET6<br />
UNIX time seconds<br />
Mili seconds first seen<br />
UNIX time seconds<br />
Mili seconds first seen<br />
Protocol<br />
Src address as 4 consecutive 32bit<br />
numbers<br />
Src port<br />
Dst address as 4 consecutive 32bit<br />
numbers.<br />
Dst port<br />
Src AS number<br />
Dst AS number<br />
Input Interface<br />
Output Interface<br />
000001 FIN.<br />
000010 SYN<br />
000100 RESET<br />
001000 PUSH<br />
010000 ACK<br />
100000 URGENT<br />
Type of Service<br />
Packets<br />
Bytes<br />
Nino Ciurleo, Alessandro Inzerilli, Simona Venuti<br />
GARR WS9, Roma, 15.06.2009<br />
96