[ARGUS] The devil is finding work for idle hands again ...

Peter Van Epp vanepp at sfu.ca
Wed Apr 14 17:07:20 EDT 2004


	Being almost ready to start playing with tcpreplay in full duplex 
mode (except tcpreplay doesn't want to play in my full duplex mode :-)) I
tried feeding a tcpdump file to argus_bpf from rc3:

/usr/local/bin/argus_bpf -r rx.tcpd | /usr/local/bin/ra -c -n 
ra: no data in data stream.
%

adding in a -w rx.argus gets nothing (presumably no output file because no 
data?):

%/usr/local/bin/argus_bpf -r rx.tcpd -w rx.argus
%ls -l
total 5602
drwxr-xr-x  3 root  wheel      512 Mar 29 11:32 archive
-rw-r--r--  1 root  wheel  3319294 Apr 13 14:57 rx.tcpd
-rw-r--r--  1 root  wheel  2368044 Apr 13 14:57 tx.tcpd

	Is this operator error of some kind again? The argus man page says it
should digest a tcpdump file with the -r  flag.

Peter Van Epp / Operations and Technical Support 
Simon Fraser University, Burnaby, B.C. Canada



More information about the argus mailing list