Missing sport / dport for Argus 3.0.8
Kjell Tore Fossbakk via Argus-info
argus-info at lists.andrew.cmu.edu
Mon Apr 4 09:10:27 EDT 2016
Im running Argus Version 3.0.8 (same with clients) with libpcap 1.5.3.
Previously we ran Argus Version 188.8.131.52 with libpcap 1.1.1.
We use ra with DELIMITERS "," and a list of fields, such as sport and
dport. If we have an ICMP with sport=0, or TCP/UDP with sport=0/dport=0 and
run this through both these Argus versiosn we get the following behavior;
Using Argus 184.108.40.206 with libpcap 1.1.1 we get 0x0000 as sport for ICMP.
Using Argus 220.127.116.11 with libpcap 1.1.1 we get 0 as sport / dport for
For 18.104.22.168.1 we would seem to get sport 0 as icmp type=0, and sport 8 as
When Now, when we use the newest version;
Using Argus 3.0.8 with libpcap 1.5.3 we get <empty data> as sport for ICMP
where we got 0x0000 for 22.214.171.124
Using Argus 3.0.8 with libpcap 1.5.3 we get <empty data> as sport/dport for
TCP/UDP where we got sport/dport 0 for 126.96.36.199
By <empty data> we mean there is nothing between the delimited on the
I'v tried to read ChangeLogs, CHANGES etc in argus, argus-clients, libpcap.
Also did a little "grepping" without much success.
So, something must have changed. Question is was the change in Argus or
libpcap? Was it deliberate, or is this a bug?
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the argus