(Fwd) Re: Analyzing tons of logs
"Bill Scherr IV" <[email protected]>
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
DOH! Sorry! editcap is the utility that will divide pcap files into arbitrary slices. You will have to provide your iterative loop of choice. Wireshark comes with that too! B. ------- Forwarded message follows ------- From: Bill Scherr IV <[email protected]> To: "Chetan Gupta" <[email protected]> Subject: Re: [logs] Analyzing tons of logs Copies to: [email protected] Send reply to: [email protected] Date sent: Fri, 30 Mar 2007 00:05:00 -0500 Hi There... I assume this is packet data (ie. libpcap). I am amazed that no one mentioned tethereal (or is it twireshark now). Regardless of the data size, you will have to have at least three times the disk space to do any kind of evidentiary work on to begin with. I am sure that was part of the engagement planning, as you seem to be in possession of the data. Regardless, most of the work can be done {bandwidth snip} > Thanks again, > > -- > Chetan Gupta ENCE, GCIA, GCFA, CEH, CCNA, CIW Sec. Analyst > Forensic Consultant > > Mobile: +91 9810718489 > ------------------------------------------------------ > Online Computer Forensics Magazine > http://www.niiconsulting.com/checkmate > ------------------------------------------------------ > ------- End of forwarded message -------Bill Scherr IV, GSEC, GCIA Principal Security Engineer EWA Information and Infrastructure Technologies [email protected] [email protected] 703-478-7608