Re: Malfunctioning of argus -S option for some pcaps
[email protected] Tue, 2 Jul 2019 21:26:54 -0400
| Newsgroups | gmane.network.argus |
|---|---|
| Message-ID | <[email protected]> |
--Apple-Mail=_D083FC38-8339-456C-954B-5CBE425BA760 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 Hey Hang, The problem is that your packets are not in time order, so argus is = doing the right thing. Best example is around packet # 3848, where the = packet timestamps jumps back 6.5 hours. Nothing argus can do with that = but tally the packets =E2=80=A6 and all the flows will be messed up for = a little while, until the packet timestamps move ahead in front of the = largest startime. If you can get the packets sorted in time, then = things should work fine. Carter > On Jul 2, 2019, at 4:19 PM, Hang Guo <[email protected]> wrote: >=20 > Hi, >=20 > I found argus -S option malfunctioning for some pcaps. For example, = when running argus -S 10 with the pcap attached (MAC and IP anamoyzed, = payload dropped for privacy), instead of reportting every 5-tuple flows = every 10 seconds, duration of some reported 5-tuple flows (as pasted = below) are hundreds of seconds. Just wonder what is the possible cause = and is there a fix to this? >=20 > argus -S 10 -r dur_test_anon.pcapng -w - | ra -c "," -r - -s dur | = sort -nr | head -5 > 4865.550781 > 296.601562 > 296.393066 > 294.411255 > 292.840790 >=20 > Thanks, > -Hang=20 > <dur_test_anon.pcapng> --Apple-Mail=_D083FC38-8339-456C-954B-5CBE425BA760 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; = charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; = -webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">Hey = Hang,<div class=3D"">The problem is that your packets are not in time = order, so argus is doing the right thing. Best example is around = packet # 3848, where the packet timestamps jumps back 6.5 hours. = Nothing argus can do with that but tally the packets =E2=80=A6 and = all the flows will be messed up for a little while, until the packet = timestamps move ahead in front of the largest startime. If you can = get the packets sorted in time, then things should work fine.</div><div = class=3D""><br class=3D""><div class=3D"">Carter<br class=3D""> <div><br class=3D""><blockquote type=3D"cite" class=3D""><div = class=3D"">On Jul 2, 2019, at 4:19 PM, Hang Guo <<a = href=3D"mailto:[email protected]" class=3D"">[email protected]</a>> = wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D""><div = dir=3D"ltr" class=3D"">Hi,<div class=3D""><br class=3D""></div><div = class=3D""><div class=3D"">I found argus -S option malfunctioning for = some pcaps. For example, when running argus -S 10 with the pcap attached = (MAC and IP anamoyzed, payload dropped for privacy), instead of = reportting every 5-tuple flows every 10 seconds, duration of some = reported 5-tuple flows (as pasted below) are hundreds of seconds. Just = wonder what is the possible cause and is there a fix to this?</div><div = class=3D""><br class=3D""></div><blockquote class=3D"gmail_quote" = style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid = rgb(204,204,204);padding-left:1ex">argus -S 10 -r dur_test_anon.pcapng = -w - | ra -c "," -r - -s dur | sort -nr | head -5<br = class=3D"">4865.550781<br class=3D"">296.601562<br = class=3D"">296.393066<br class=3D"">294.411255<br = class=3D"">292.840790</blockquote><div class=3D""><br = class=3D""></div><div class=3D"">Thanks,</div><div = class=3D"">-Hang </div></div></div> <span = id=3D"cid:f_jxm9ab750"><dur_test_anon.pcapng></span></div></blockquo= te></div><br class=3D""></div></div></body></html>= --Apple-Mail=_D083FC38-8339-456C-954B-5CBE425BA760--