applications/system

silk-rwflowpack - SiLK Toolset: The Packer

Website: http://tools.netsa.cert.org/silk/
License: GPLv2
Vendor: CERT Network Situational Awareness <netsa-help@cert.org>
Description:
SiLK, the System for Internet-Level Knowledge, is a collection of
traffic analysis tools developed by the CERT Network Situational
Awareness Team (CERT NetSA) to facilitate security analysis of large
networks. The SiLK tool suite supports the efficient collection,
storage and analysis of network flow data, enabling network security
analysts to rapidly query large historical traffic data sets. SiLK is
ideally suited for analyzing traffic on the backbone or border of a
large, distributed enterprise or mid-sized ISP.

The silk-rwflowpack package converts NetFlow v5 or IPFIX (Internet
Protocol Flow Information eXport) data to the SiLK Flow record format,
categorizes each flow (e.g., as incoming or outgoing), and stores the
data in binary flat files within a directory tree, with one file per
hour-category-sensor tuple.  Use the tools from the silk-analysis
package to query this data.  rwflowpack may capture the data itself,
or it may process files that have been created by flowcap (see the
silk-flowcap package).

Packages

silk-rwflowpack-3.17.2-1.fc27.i686 [192 KiB] Changelog by Lawrence Rogers (2018-06-28):
* Release 3.17.2-1/2
	rwgeoip2ccmap
		Add a --fields switch that gives the user control over which country-code value(s) are used when reading a GeoIP2 file.
	rwuniq
		Use a 64-bit integer for storing a bin's record count.
	rwstats
		Use a 64-bit integer for storing a bin's record count.
	rwaddrcount
		Use 64-bit integers for storing a bin's packet count and record count.
	rwflowpack
		In sensor.conf, add a new quirk, nf9-out-is-reverse, to simulate the behavior of libfixbuf-1.7.1; i.e., to treat the NetFlow v9 elements OUT_BYTES and OUT_PKTS as reverse-volume values.
		When parsing the sensor.conf file, allow double-quoted strings for the path names of IPset files.
	flowcap
		In sensor.conf, add a new quirk, nf9-out-is-reverse, to simulate the behavior of libfixbuf-1.7.1; i.e., to treat the NetFlow v9 elements OUT_BYTES and OUT_PKTS as reverse-volume values.
silk-rwflowpack-3.17.1-1.fc27.i686 [191 KiB] Changelog by Lawrence Rogers (2018-04-23):
* Release 3.17.1-1/2
	3.17.1
		Fix a compilation failure on RedHat EL6, CentOS 6, and other systems.
	3.17.0
		Add support in rwaggbagtool for removing rows when a value is above or below a threashold or when an 
			IP address is in or is not in an IPset.
		Change how rwsetcat displays IPv4 addresses in an IPset containing both IPv4 and IPv6 addresses.
		Add support for millisecond timestamps in rwuniq and rwstats.
		Add support for the GeoIP2 version of MaxMind's country code comma-separated value files and binary files.
			(Binary file support requires libmaxminddb library support.)
silk-rwflowpack-3.16.1-1.fc27.i686 [190 KiB] Changelog by Lawrence Rogers (2018-02-15):
* Release 3.16.1-1/2
	rwstats
		Fix a bug that occurred when using a large amount of memory and could result in corrupted output.
	rwuniq
		Fix a bug that occurred when using a large amount of memory and could result in corrupted output.
	rwbagcat
		Fix bugs that occur when using the --network-structure switch with an IPv4-specific argument and bag file contains addresses in the ::ffff:0:0/96 netblock.
	rwsetcat
		Print an error message when rwsetcat is unable to read an IPset.
	rwsender, rwreceiver
		Fix an issue when using installations of GnuTLS that do not provide support for thread locking.
	rwflowpack, flowcap
		Fix a bug where NetFlow v9 records were being ignored because the application was decoding them with the wrong internal template.
	Building
		Fix issues when determining compilation flags necessary for Python support.
silk-rwflowpack-3.16.0-3.fc27.i686 [194 KiB] Changelog by Lawrence Rogers (2017-11-09):
* Release 3.16.0-3/4
	Rebuilt with libfixbuf 1.8.0.

Listing created by Repoview-0.6.6-1.el6