silk - SiLK: A network flow collection and analysis package
|Vendor:||CERT Network Situational Awareness <firstname.lastname@example.org>|
SiLK, the System for Internet-Level Knowledge, is a collection of traffic analysis tools developed by the CERT Network Situational Awareness Team (CERT NetSA) to facilitate security analysis of large networks. The SiLK tool suite supports the efficient collection, storage and analysis of network flow data, enabling network security analysts to rapidly query large historical traffic data sets. SiLK is ideally suited for analyzing traffic on the backbone or border of a large, distributed enterprise or mid-sized ISP. SiLK consists of two sets of tools: a packing system and analysis suite. The packing system receives network flow information from Netflow v5 or any IPFIX-based flowmeter and converts them into a more space efficient format, recording the packed records into service-specific, binary flat files. The analysis suite consists of tools which can read these flat files and then perform various query operations, ranging from per-record filtering to statistical analysis of groups of records. The analysis tools interoperate using pipes, allowing a user to develop a relatively sophisticated query from a simple beginning.
|silk-3.19.0-1.fc28.src [5.4 MiB]||
by Lawrence R. Rogers (2019-10-24):
* Release 3.19.0-1/2 rwaggbag, rwaggbagbuild, rwaggbagcat, rwaggbagtool Support using country codes as key fields. rwflowpack, flowcap Support a show-templates log-flag value in the sensors.conf file which enables printing of templates for specific probes.