Flow loss metric

Pablo J. Rebollo-Sosa Pablo.Rebollo at ece.uprm.edu
Sat Apr 10 09:18:38 EDT 2010


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

I was using Argus to determine traffic loss and noticed odd results.  To
recreate the scenario a file was transfered trough the loopback and
captured with tshark.  Then the dump was analyzed with argus with the
following results:

> argus -X -r tsharkcapture-lo -w - | ra -n -L 1 -s saddr sport dir daddr dport pkts spkts dpkts loss sloss dloss ploss
>            SrcAddr  Sport   Dir            DstAddr  Dport  TotPkts  SrcPkts  DstPkts       Loss    SrcLoss    DstLoss    pLoss 
>          127.0.0.1.46929     ->          127.0.0.1.80           58       28       30         54         26         28 48.21428

I can't understand that 58 packets were captured and 54 of them were
lost.  There is something wrong?

Attached is the captured file.

Best regards,

Pablo J. Rebollo-Sosa

- ---
Argus Version 3.0.3.3
Ra Version 3.0.3.6

Serve the file
mini-httpd -d ARGUS/

Loopback capture
tshark -s 0 -i lo -w tsharkcapture-lo

Download file
wget http://127.0.0.1/argus-3.0.3.3.tar.gz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkvAeq4ACgkQxjU5UYZ6K6fa4wCfeyp+D4ySDSE3fSBiGeyoOzRj
sNkAn2aMfyuSIKIydHbiWHfJI/TuF2aV
=37gf
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: tsharkcapture-lo
Type: application/octet-stream
Size: 427768 bytes
Desc: not available
URL: <https://pairlist1.pair.net/pipermail/argus/attachments/20100410/dbf6dd6a/attachment.obj>


More information about the argus mailing list