Aggregate data from two sources

Patrick Forsberg via Argus-info argus-info at
Fri Nov 4 07:54:10 EDT 2016


I have a question on how to merge flows from two sources.

We have an active-active router configuration that means traffic can
come in through one router and go out through the other.

We have argus listeners at each router through passive taps. The problem
that we have is that flows involving both routers will not aggregate.

The following example shows to flows that should really only be one flow.

             StartTime      Flgs  Proto            SrcAddr  Sport   Dir            DstAddr  Dport  SrcPkts  DstPkts State            SrcId 
161031 23:58:46.089721  e           tcp     ->        522        0   RST
161031 23:58:46.089953  e           tcp      ->       353        0   CON

Patrick Forsberg
Chalmers University of Technology

