[root@mail 26]# ls
nfcapd.201512261440 nfcapd.201512261445 nfcapd.201512261450 nfcapd.201512261455
List Flows:
nfdump -r nfcapd.201512261440 -c 10
data:image/s3,"s3://crabby-images/cba1c/cba1cc91548bd6eb5cafd18e7e01762f0ae6ba67" alt=""
Create TopN Statistics Packets/Bytes:
nfdump -r nfcapd.201512261440 -n 10 -s record/bytesnfdump -r nfcapd.201512261440 -n 10 -s record/packets
data:image/s3,"s3://crabby-images/2ee56/2ee56bd6d61a92abd3ee2de3f0a7b4b6feadb876" alt=""
Create TopN statistics IP addresses, Ports:
nfdump -r nfcapd.201512261440 -n 10 -s dstport
nfdump -r nfcapd.201512261440 -n 10 -s srcip
List the first 20 tcp flows:
nfdump -r nfcapd.201512261440 -c 20 'proto tcp'
data:image/s3,"s3://crabby-images/11bd2/11bd27641df44e41877fab7535ef10fe15ae4b83" alt=""
Show the top 15 IP addresses consuming most bandwidth
nfdump -r nfcapd.201512261440 -n 15 -s ip/bps
data:image/s3,"s3://crabby-images/0b266/0b266e051f8a74917c1b3d2fa3951876a8a67b65" alt=""
Show port scanning candidates:
nfdump -r nfcapd.201512261440 -A srcip,dstport -s record/packets 'not proto icmp and bytes < 100
and bpp < 100 and packets < 5 and not port 80 and not port 53 and not port 110 and not port 123'
Show the top 15 /24 subnets exchanging most traffic:
0 回應:
張貼留言