[WISHLIST] How many records to output
nick at engineerity.com
Thu Sep 11 12:06:32 EDT 2008
A work around I use:
ra -r file.argus -w - - "filter" | ra -r - -N 100
Unfortunately the first ra process will go through the entire file, so if
processing time is a concern...
On Thu, Sep 11, 2008 at 7:47 AM, Tomoyuki Sakurai <cherry at trombik.org>wrote:
> Currently, argus clients have no option to specify how many record to
> output (-N option is how many record to process). This is especially
> useful when you need to know if there is a flow using specific dst port.
> With this option and if you are lucky, you don't have to scan entire file.
> Also, it would be useful to be able to specify next N of records, like
> "2nd 100 flows that matches the filter expression". This is useful for
> pager operation (the one you'll find in a web application like [<<] 
>  [>>]).
> Best regards,
> Tomoyuki Sakurai
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the argus