⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 flow-export.html

📁 netflow,抓包
💻 HTML
字号:
<HTML><HEAD><TITLE>flow-export</TITLE><METANAME="GENERATOR"CONTENT="Modular DocBook HTML Stylesheet Version 1.73"></HEAD><BODYCLASS="REFENTRY"BGCOLOR="#FFFFFF"TEXT="#000000"LINK="#0000FF"VLINK="#840084"ALINK="#0000FF"><H1><ANAME="AEN1"><SPANCLASS="APPLICATION">flow-export</SPAN></A></H1><DIVCLASS="REFNAMEDIV"><ANAME="AEN6"></A><H2>Name</H2><SPANCLASS="APPLICATION">flow-export</SPAN>&nbsp;--&nbsp;Export flow-tools files into other NetFlow packages.</DIV><DIVCLASS="REFSYNOPSISDIV"><ANAME="AEN10"></A><H2>Synopsis</H2><P><BCLASS="COMMAND">flow-export</B>  [-h] [-d<TTCLASS="REPLACEABLE"><I> debug_level</I></TT>] [-f<TTCLASS="REPLACEABLE"><I> format</I></TT>] [-m<TTCLASS="REPLACEABLE"><I> mask_fields</I></TT>] [-u<TTCLASS="REPLACEABLE"><I> user:password:host:port:name:table</I></TT>]</P></DIV><DIVCLASS="REFSECT1"><ANAME="AEN22"></A><H2>DESCRIPTION</H2><P>The <BCLASS="COMMAND">flow-export</B> utility will convert flow-toolsflow files to ASCII CSV, cflowd, or pcap format.</P></DIV><DIVCLASS="REFSECT1"><ANAME="AEN26"></A><H2>OPTIONS</H2><P></P><DIVCLASS="VARIABLELIST"><DL><DT>-d<TTCLASS="REPLACEABLE"><I> debug_level</I></TT></DT><DD><P>Enable debugging.</P></DD><DT>-f<TTCLASS="REPLACEABLE"><I> format</I></TT></DT><DD><P>Export format.  Supported formats are:  0 cflowd  1 pcap  2 ASCII CSV  3 MySQL  4 wire</P></DD><DT>-h</DT><DD><P>Display help.</P></DD><DT>-m<TTCLASS="REPLACEABLE"><I> mask_fields</I></TT></DT><DD><P>Select fields for cflowd and ASCII formats.  The<TTCLASS="REPLACEABLE"><I>mask_fields</I></TT>is built from a bitwise OR of the following:</P><P><PRECLASS="SCREEN">    UNIX_SECS       0x0000000000000001LL    UNIX_NSECS      0x0000000000000002LL    SYSUPTIME       0x0000000000000004LL    EXADDR          0x0000000000000008LL        DFLOWS          0x0000000000000010LL    DPKTS           0x0000000000000020LL    DOCTETS         0x0000000000000040LL    FIRST           0x0000000000000080LL        LAST            0x0000000000000100LL    ENGINE_TYPE     0x0000000000000200LL    ENGINE_ID       0x0000000000000400LL        SRCADDR         0x0000000000001000LL    DSTADDR         0x0000000000002000LL    SRC_PREFIX      0x0000000000004000LL    DST_PREFIX      0x0000000000008000LL    NEXTHOP         0x0000000000010000LL    INPUT           0x0000000000020000LL    OUTPUT          0x0000000000040000LL    SRCPORT         0x0000000000080000LL        DSTPORT         0x0000000000100000LL    PROT            0x0000000000200000LL    TOS             0x0000000000400000LL    TCP_FLAGS       0x0000000000800000LL        SRC_MASK        0x0000000001000000LL    DST_MASK        0x0000000002000000LL    SRC_AS          0x0000000004000000LL    DST_AS          0x0000000008000000LL        IN_ENCAPS       0x0000000010000000LL    OUT_ENCAPS      0x0000000020000000LL    PEER_NEXTHOP    0x0000000040000000LL    ROUTER_SC       0x0000000080000000LL    EXTRA_PKTS      0x0000000100000000LL    MARKED_TOS      0x0000000200000000LL</PRE></P><P>When exporting to cflowd format the <TTCLASS="REPLACEABLE"><I>mask_fields</I></TT>field is the cflowd mask which is defined as the following:</P><P><PRECLASS="SCREEN">    ROUTERMASK         0x00000001    SRCIPADDRMASK      0x00000002    DSTIPADDRMASK      0x00000004    INPUTIFINDEXMASK   0x00000008    OUTPUTIFINDEXMASK  0x00000010    SRCPORTMASK        0x00000020    DSTPORTMASK        0x00000040    PKTSMASK           0x00000080    BYTESMASK          0x00000100    IPNEXTHOPMASK      0x00000200    STARTTIMEMASK      0x00000400    ENDTIMEMASK        0x00000800    PROTOCOLMASK       0x00001000    TOSMASK            0x00002000    SRCASMASK          0x00004000    DSTASMASK          0x00008000    SRCMASKLENMASK     0x00010000    DSTMASKLENMASK     0x00020000    TCPFLAGSMASK       0x00040000    INPUTENCAPMASK     0x00080000    OUTPUTENCAPMASK    0x00100000    PEERNEXTHOPMASK    0x00200000    ENGINETYPEMASK     0x00400000    ENGINEIDMASK       0x00800000        INDEX_V1_MASK      0x00043FFF    INDEX_V5_MASK      0x00C7FFFF    INDEX_V6_MASK      0x00FFFFFF    INDEX_V7_MASK      0x00C7FFFF    INDEX_V8_1_MASK    0x00C0CD99    INDEX_V8_2_MASK    0x00C00DE1    INDEX_V8_3_MASK    0x00C14D8B    INDEX_V8_4_MASK    0x00C28D95    INDEX_V8_5_MASK    0x00C3CD9F</PRE> </P><P>The default value is all fields applicable to the the flow file, orthe cflowd INDEX mask applicabable to the export format.</P></DD><DT>-u<TTCLASS="REPLACEABLE"><I> user:password:host:port:name:table</I></TT></DT><DD><P>Configure MySQL Access.</P></DD></DL></DIV></DIV><DIVCLASS="REFSECT1"><ANAME="AEN61"></A><H2>EXAMPLES</H2><DIVCLASS="INFORMALEXAMPLE"><ANAME="AEN63"></A><P></P><P>Convert the flow-tools file <TTCLASS="FILENAME">flows</TT> to the cflowdfile <TTCLASS="FILENAME">flows.cflowd</TT>.  Include all fields.</P><P>  <BCLASS="COMMAND">flow-export -f0 &lt; flows &#62; flows.cflowd</B></P><P></P></DIV></DIV><DIVCLASS="REFSECT1"><ANAME="AEN69"></A><H2>EXAMPLES</H2><DIVCLASS="INFORMALEXAMPLE"><ANAME="AEN71"></A><P></P><P>Convert the flow-tools file <TTCLASS="FILENAME">flows</TT> to the ASCII.  Includethe SRCADDR and DSTADDR fields.</P><P>  <BCLASS="COMMAND">flow-export -f2 -m0x3000 &lt; flows &#62; flows.ascii</B></P><P></P></DIV></DIV><DIVCLASS="REFSECT1"><ANAME="AEN76"></A><H2>BUGS</H2><P>The pcap format is a hack.</P></DIV><DIVCLASS="REFSECT1"><ANAME="AEN79"></A><H2>AUTHOR</H2><P>Mark Fullmer<TTCLASS="EMAIL">&#60;<AHREF="mailto:maf@splintered.net">maf@splintered.net</A>&#62;</TT></P></DIV><DIVCLASS="REFSECT1"><ANAME="AEN86"></A><H2>SEE ALSO</H2><P><SPANCLASS="APPLICATION">flow-tools</SPAN>(1)</P></DIV></BODY></HTML>

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -