nanog mailing list archives
analyse tcpdump output
From: Stefan Hegger <Stefan.Hegger () lycos-europe com>
Date: Wed, 22 Nov 2006 16:34:13 +0100
Hi, I wonder if someone knows a tool to use a tcpdump output for anomaly dedection. It is sometimes really time consuming when looking for identical patterns in the tcpdump output. It would be helpful to get a diff between SYN and ACK's e.g. Or look for a pattern in a URL. Or just get some timediffs e.g. when an ACK is send but client is waiting for data etc. We would like to decrease time to investigate the cause for an unusual network behaviour. Best Stefan -- Stefan Hegger Internet System Engineer Stefan.Hegger () lycos-europe com Tel: +49 5241 8071 334 Lycos Europe GmbH Carl-Bertelsmann Str. 29 Postfach 315 33311 Gütersloh
Current thread:
- analyse tcpdump output Stefan Hegger (Nov 22)
- Re: analyse tcpdump output Rodrick Brown (Nov 22)
- RE: analyse tcpdump output Brock, Anthony - NET (Nov 22)
- Re: analyse tcpdump output William Waites (Nov 22)
- Re: analyse tcpdump output Netfortius (Nov 22)
- Re: analyse tcpdump output Roland Dobbins (Nov 22)
- Re: analyse tcpdump output David Nolan (Nov 24)
- Re: analyse tcpdump output Jason Chambers (Nov 25)
- Re: analyse tcpdump output Jason Chambers (Nov 25)
- Re: analyse tcpdump output Payam (Nov 27)
- Re: analyse tcpdump output Jason Chambers (Nov 25)