tcptrace host filter

From: Ramana Yarlagadda (ramana_yarlagadda@yahoo.com)
Date: 10/06/04


Message-ID: <20041006060009.38419.qmail@web14304.mail.yahoo.com>
Date: Tue, 5 Oct 2004 23:00:09 -0700 (PDT)
From: Ramana Yarlagadda <ramana_yarlagadda@yahoo.com>
Subject: tcptrace host filter

Hi,

I am using Tcptrace to analyze traffic on a LAN.

1) First of all I would like to say that the tool was
really helpful for analyzing the traffic.

2) About my setup: Normally I capture data in a pcap
file with out setting any filters and then I am
analyzing traffic to understand the flows on the LAN.

Following are the problems that I cam across while
using the tool. I just started using the tool so I am
just wondering if sombody has the answers for the
following

a) How can I find most active hosts on the LAN using
the Tcptrace? And how can I generate plots specific to
a Host?

b) Here, I have written a small program to find most
active host(192.168.1.123) on the LAN and then I have
used following command to see plots on this specific
host using the -f option as shown below.
tcptrace '-fhostaddr=192.168.1.123' -xtraffic"-A"
etherdata.pcap

Also I have plot for
tcptrace -xtraffic"-A" etherdata.pcap

And in the plots looks same in both the cases.

Can somebody help me ...

-Thanks
-Ramana

                
_______________________________
Do you Yahoo!?
Declare Yourself - Register online to vote today!
http://vote.yahoo.com
----------------------------------------------------------------------------
To unsubscribe, send a message with body containing "unsubscribe tcptrace" to
majordomo@tcptrace.org.



This archive was generated by hypermail 2.1.7 : 10/06/04 EDT