(Fwd) Re: Analyzing tons of logs

"Bill Scherr IV" <[email protected]>
Newsgroups gmane.comp.sysutils.loganalysis
Message-ID <[email protected]>
DOH!

Sorry!  editcap is the utility that will divide pcap files into arbitrary slices.  You 
will have to provide your iterative loop of choice.

Wireshark comes with that too!

B.

------- Forwarded message follows -------
From:           	Bill Scherr IV <[email protected]>
To:             	"Chetan Gupta" <[email protected]>
Subject:        	Re: [logs] Analyzing tons of logs
Copies to:      	[email protected]
Send reply to:  	[email protected]
Date sent:      	Fri, 30 Mar 2007 00:05:00 -0500

Hi There...

I assume this is packet data (ie. libpcap).  I am amazed that no one 
mentioned tethereal (or is it twireshark 
now).  Regardless of the data size, you will have to have at least three times 
the disk space to do any kind 
of evidentiary work on to begin with.  I am sure that was part of the 
engagement planning, as you seem to 
be in possession of the data.  Regardless, most of the work can be done

{bandwidth snip}

> Thanks again,
> 
> -- 
> Chetan Gupta ENCE, GCIA, GCFA, CEH, CCNA, CIW Sec. Analyst
> Forensic Consultant
> 
> Mobile: +91 9810718489
> ------------------------------------------------------
> Online Computer Forensics Magazine
> http://www.niiconsulting.com/checkmate
> ------------------------------------------------------
> 


------- End of forwarded message -------Bill Scherr IV, GSEC, GCIA
Principal Security Engineer
EWA Information and Infrastructure Technologies
[email protected]
[email protected]
703-478-7608
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.