packet headers

Carter Bullard carter at qosient.com
Sun Mar 30 13:35:21 EDT 2014


Hey Oğuz,
Yes, use this option in the argus.conf file.

# Argus allows you to capture packets in tcpdump() format
# if the source of the packets is a tcpdump() formatted
# file or live packet source.
#
# Specify the path to the packet capture file here.
#

#ARGUS_PACKET_CAPTURE_FILE="/var/log/argus/packet.out”


You can rename the file while argus is using it, and argus will detect the move,
close and reopen another packet output file, so you can periodically process
this file.

Carter

On Mar 30, 2014, at 6:33 AM, Oğuz Yarımtepe <oguzyarimtepe at gmail.com> wrote:

> Hi,
> 
> I was quiet away from Argus usage. Now i need some info whether i can use Argus again. I would like to also analyze paket headers belonging to an Argus flow. Does Argus have an option to dump also the packet header information? Else, how can i gather suche a traffic on a Gbit network, both flow and packet information?
> 
> -- 
> Oğuz Yarımtepe
> http://about.me/oguzy

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 6837 bytes
Desc: not available
URL: <https://pairlist1.pair.net/pipermail/argus/attachments/20140330/d6420cc8/attachment.bin>


More information about the argus mailing list