Flow loss metric
Pablo J. Rebollo-Sosa
Pablo.Rebollo at ece.uprm.edu
Sat Apr 10 09:18:38 EDT 2010
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
I was using Argus to determine traffic loss and noticed odd results. To
recreate the scenario a file was transfered trough the loopback and
captured with tshark. Then the dump was analyzed with argus with the
following results:
> argus -X -r tsharkcapture-lo -w - | ra -n -L 1 -s saddr sport dir daddr dport pkts spkts dpkts loss sloss dloss ploss
> SrcAddr Sport Dir DstAddr Dport TotPkts SrcPkts DstPkts Loss SrcLoss DstLoss pLoss
> 127.0.0.1.46929 -> 127.0.0.1.80 58 28 30 54 26 28 48.21428
I can't understand that 58 packets were captured and 54 of them were
lost. There is something wrong?
Attached is the captured file.
Best regards,
Pablo J. Rebollo-Sosa
- ---
Argus Version 3.0.3.3
Ra Version 3.0.3.6
Serve the file
mini-httpd -d ARGUS/
Loopback capture
tshark -s 0 -i lo -w tsharkcapture-lo
Download file
wget http://127.0.0.1/argus-3.0.3.3.tar.gz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEARECAAYFAkvAeq4ACgkQxjU5UYZ6K6fa4wCfeyp+D4ySDSE3fSBiGeyoOzRj
sNkAn2aMfyuSIKIydHbiWHfJI/TuF2aV
=37gf
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: tsharkcapture-lo
Type: application/octet-stream
Size: 427768 bytes
Desc: not available
URL: <https://pairlist1.pair.net/pipermail/argus/attachments/20100410/dbf6dd6a/attachment.obj>
More information about the argus
mailing list