Re: Malfunctioning of argus -S option for some pcaps

[email protected] Tue, 2 Jul 2019 21:26:54 -0400
Newsgroups gmane.network.argus
Message-ID <[email protected]>
--Apple-Mail=_D083FC38-8339-456C-954B-5CBE425BA760
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hey Hang,
The problem is that your packets are not in time order, so argus is =
doing the right thing.  Best example is around packet # 3848, where the =
packet timestamps jumps back 6.5 hours.  Nothing argus can do with that =
but tally the packets =E2=80=A6 and all the flows will be messed up for =
a little while, until the packet timestamps move ahead in front of the =
largest startime.  If you can get the packets sorted in time, then =
things should work fine.

Carter

> On Jul 2, 2019, at 4:19 PM, Hang Guo <[email protected]> wrote:
>=20
> Hi,
>=20
> I found argus -S option malfunctioning for some pcaps. For example, =
when running argus -S 10 with the pcap attached (MAC and IP anamoyzed, =
payload dropped for privacy), instead of reportting every 5-tuple flows =
every 10 seconds, duration of some reported 5-tuple flows (as pasted =
below) are hundreds of seconds. Just wonder what is the possible cause =
and is there a fix to this?
>=20
> argus -S 10 -r dur_test_anon.pcapng -w - | ra -c "," -r - -s dur | =
sort -nr | head -5
> 4865.550781
> 296.601562
> 296.393066
> 294.411255
> 292.840790
>=20
> Thanks,
> -Hang=20
> <dur_test_anon.pcapng>


--Apple-Mail=_D083FC38-8339-456C-954B-5CBE425BA760
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">Hey =
Hang,<div class=3D"">The problem is that your packets are not in time =
order, so argus is doing the right thing. &nbsp;Best example is around =
packet # 3848, where the packet timestamps jumps back 6.5 hours. =
&nbsp;Nothing argus can do with that but tally the packets =E2=80=A6 and =
all the flows will be messed up for a little while, until the packet =
timestamps move ahead in front of the largest startime. &nbsp;If you can =
get the packets sorted in time, then things should work fine.</div><div =
class=3D""><br class=3D""><div class=3D"">Carter<br class=3D"">
<div><br class=3D""><blockquote type=3D"cite" class=3D""><div =
class=3D"">On Jul 2, 2019, at 4:19 PM, Hang Guo &lt;<a =
href=3D"mailto:[email protected]" class=3D"">[email protected]</a>&gt; =
wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D""><div =
dir=3D"ltr" class=3D"">Hi,<div class=3D""><br class=3D""></div><div =
class=3D""><div class=3D"">I found argus -S option malfunctioning for =
some pcaps. For example, when running argus -S 10 with the pcap attached =
(MAC and IP anamoyzed, payload dropped for privacy), instead of =
reportting every 5-tuple flows every 10 seconds, duration of some =
reported 5-tuple flows (as pasted below) are hundreds of seconds. Just =
wonder what is the possible cause and is there a fix to this?</div><div =
class=3D""><br class=3D""></div><blockquote class=3D"gmail_quote" =
style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid =
rgb(204,204,204);padding-left:1ex">argus -S 10 -r dur_test_anon.pcapng =
-w - | ra -c "," -r - -s dur | sort -nr | head -5<br =
class=3D"">4865.550781<br class=3D"">296.601562<br =
class=3D"">296.393066<br class=3D"">294.411255<br =
class=3D"">292.840790</blockquote><div class=3D""><br =
class=3D""></div><div class=3D"">Thanks,</div><div =
class=3D"">-Hang&nbsp;</div></div></div>
<span =
id=3D"cid:f_jxm9ab750">&lt;dur_test_anon.pcapng&gt;</span></div></blockquo=
te></div><br class=3D""></div></div></body></html>=

--Apple-Mail=_D083FC38-8339-456C-954B-5CBE425BA760--