silk-flowcap - SiLK Toolset: Remote Flow Collection
|Vendor:||CERT Network Situational Awareness <firstname.lastname@example.org>|
SiLK, the System for Internet-Level Knowledge, is a collection of traffic analysis tools developed by the CERT Network Situational Awareness Team (CERT NetSA) to facilitate security analysis of large networks. The SiLK tool suite supports the efficient collection, storage and analysis of network flow data, enabling network security analysts to rapidly query large historical traffic data sets. SiLK is ideally suited for analyzing traffic on the backbone or border of a large, distributed enterprise or mid-sized ISP. The silk-flowcap package contains flowcap, a daemon to capture NetFlow v5 or IPFIX flows (Internet Protocol Flow Information eXport), to store the data temporarily in files on its local disk, and to forward these files over the network to a machine where rwflowpack processes the data. flowcap is typically used with an rwsender-rwreceiver pair to move the files across the network.
|silk-flowcap-184.108.40.206-1.fc17.i686 [41 KiB]||
by Lawrence Rogers (2015-10-08):
* Release 220.127.116.11-1/2 18.104.22.168 Fix linking issue on Ubuntu when PySiLK support is enabled. 3.11.0 Allow rwsiteinfo to report on date ranges of files in a SiLK repository. Provide a way to set the default textual timestamp format and timezone from the environment. Provide a way to set the default textual IP format from the environment. Compile the PySiLK plug-in into the tools that can use it. Remove support for fixbuf releases prior to libfixbuf-1.6.0. Make additional changes and bug fixes.
|silk-flowcap-2.4.7-2.fc17.i386 [32 KiB]||
by Lawrence Rogers (2012-03-29):
* Release 2.4.7-2 Now uses adns