I am trying to see what kind of traffic is listed in the Stream Log, what each column in the log file say, need to parse the log to understand it,
thanks Meir
Article Comments
Attention: This article is a record of a conversation with the Paessler support team. The information in this conversation is not updated to preserve the historical record. As a result, some of the information or recommendations in this conversation might be out of date.
hey, thanks for quick respond, but now how i know what the meaning of every column ? first,second,third column is date of what ? what is 56231,6,10.0.0.1,286, and so on until the end, sorry if i don't explain my question,
I add few lines to show ..
|28-02-17 16:43|28-02-17 14:43|28-02-17 14:43|27678|1|199.203.158.61|13509|00-00-00-00-00-00|199.203.1.20|53|00-00-00-00-00-00|122|1018|0|199.203.158.61|2|7|0|0|0|0|0.0.0.0|0|0| |28-02-17 16:43|28-02-17 14:43|28-02-17 14:43|63317|17|199.203.1.20|53|00-00-00-00-00-00|199.203.158.61|13509|00-00-00-00-00-00|116|1004|0|199.203.158.61|7|2|0|0|0|0|0.0.0.0|0|0| |28-02-17 16:43|28-02-17 14:43|28-02-17 14:43|14636|1|199.203.158.61|30772|00-00-00-00-00-00|199.203.1.20|53|00-00-00-00-00-00|135|1018|0|199.203.158.61|2|7|0|0|0|0|0.0.0.0|0|0|
thanks again
Mar, 2017 - Permalink
This is the heading for the Netflow streamlog:
Now,FromDateTime,ToDateTime,EthernetType,Protocol,SourceIP,SourcePort,SourceMAC,DestinationIP,DestinationPort,DestinationMAC,Size,ChannelID,ToS,SenderIP,InboundInterface,OutboundInterface,SourceASI,DestinationASI,SourceMask,DestinationMask,NextHop,SourceVLAN,DestinationVLAN
Mar, 2017 - Permalink
The "best trick" to analyze them is to copy them out of the StreamLog folder. Then, open the file in notepad (or similar) and add the following to the begining of the file:
SEP=,
It should look like this:
Now, you can open the file in excel and it should be legible. Something like this(This is from a Packet Sniffer sensor):
The fields will include the information listed here:
Basically you'll have some general properties, and then the IP/Port/Mac Source and the IP/Port/Mac destination.
Mar, 2017 - Permalink