Removing possibly unused metadata?

Jason Carr jcarr at andrew.cmu.edu
Fri Oct 28 17:06:59 EDT 2011


We write argus data into five minute chunked files.  We typically have +1G
files for those 5 minutes.  Is there any metadata that we might be able to
purge to decrease the size significantly?

I normally only care about StartTime, flags, pro to, src/dst
{mac,ip,port}, direction, packets, bytes, state, and user data in either
direction.

I already gzip compress the files, I tried using bzip2 on a few test files
and got a 1.1G file down to 500M instead of 539M, but I'm looking for a
larger compression and/or size difference.

Thanks,

Jason




More information about the argus mailing list