silk-rwflowpack - SiLK Toolset: The Packer
Website: | http://tools.netsa.cert.org/silk/ |
---|---|
License: | GPLv2 |
Vendor: | CERT Network Situational Awareness <netsa-help@cert.org> |
- Description:
SiLK, the System for Internet-Level Knowledge, is a collection of traffic analysis tools developed by the CERT Network Situational Awareness Team (CERT NetSA) to facilitate security analysis of large networks. The SiLK tool suite supports the efficient collection, storage and analysis of network flow data, enabling network security analysts to rapidly query large historical traffic data sets. SiLK is ideally suited for analyzing traffic on the backbone or border of a large, distributed enterprise or mid-sized ISP. The silk-rwflowpack package converts NetFlow v5 or IPFIX (Internet Protocol Flow Information eXport) data to the SiLK Flow record format, categorizes each flow (e.g., as incoming or outgoing), and stores the data in binary flat files within a directory tree, with one file per hour-category-sensor tuple. Use the tools from the silk-analysis package to query this data. rwflowpack may capture the data itself, or it may process files that have been created by flowcap (see the silk-flowcap package).
Packages
silk-rwflowpack-3.19.0-2.fc25.i686 [193 KiB] |
Changelog
by Lawrence R. Rogers (2019-10-24):
* Release 3.19.0-1/2 rwaggbag, rwaggbagbuild, rwaggbagcat, rwaggbagtool Support using country codes as key fields. rwflowpack, flowcap Support a show-templates log-flag value in the sensors.conf file which enables printing of templates for specific probes. |
silk-rwflowpack-3.18.3-2.fc25.i686 [193 KiB] |
Changelog
by Lawrence R. Rogers (2019-08-29):
* Release 3.18.3-1/2 Quiet a warning message when using libfixbuf-2.4.0. |