pcaps:ixmgtool
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| pcaps:ixmgtool [2019/04/13 19:11] – [Example run] veera | pcaps:ixmgtool [2019/04/15 16:50] (current) – [Conclusion] veera | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== Merge multiple thin PCAP files into a single | + | ====== Merge multiple thin PCAP files into a single |
| When you install Trisul Network Analytics , you get a free command line tool called '' | When you install Trisul Network Analytics , you get a free command line tool called '' | ||
| Line 7: | Line 7: | ||
| ===== What is a FAT pcap file ===== | ===== What is a FAT pcap file ===== | ||
| - | A FAT pcap file contains more unique flows and endpoints than a THIN pcap file. | + | < |
| + | </ | ||
| While testing NSM((Network Security Monitoring)) | While testing NSM((Network Security Monitoring)) | ||
| Line 17: | Line 18: | ||
| ===== How is it different from mergecap | ===== How is it different from mergecap | ||
| - | Mergecap | + | Mergecap |
| - | trisul_ixmgtool when run with the squish option , aligns the timestamps | + | trisul_ixmgtool when run with the squish option , aligns the timestamps |
| {{: | {{: | ||
| + | You can think of ixmgtool as combining the following three operations | ||
| + | - Find the lowest timestamp from all the pcap files, and compute the deltas for each file | ||
| + | - Run '' | ||
| + | - Run '' | ||
| - | ====== trisul_ixmgtool ====== | + | ====== |
| To get the free ixmgtool [[https:// | To get the free ixmgtool [[https:// | ||
| Line 48: | Line 53: | ||
| ===== Example run ===== | ===== Example run ===== | ||
| - | Say you have put 10 files in a directory | + | Say you have put 10 files in a directory |
| < | < | ||
| Line 97: | Line 102: | ||
| - | To get a **really | + | To get a **really |
| Line 125: | Line 130: | ||
| ====== Conclusion ====== | ====== Conclusion ====== | ||
| + | trisul_ixmgtool | ||
| - | The trisul_ixmgtool part of the Trisul | + | Hope this is useful to the NSM community. |
| - | Using the squish options you can create a mega thick PCAP file for testing by throwing all your PCAP testing files in single directory from varying timestamps and creating a single thick one. | ||
| - | Hope this is useful for the NSM community. | + | To get the tool (it is free). |
| - | + | ||
| - | + | ||
| - | To get the tool : Install the Trisul Probe package for your platform from the [[https:// | + | |
pcaps/ixmgtool.1555162910.txt.gz · Last modified: 2019/04/13 19:11 by veera