Linux and UNIX Man Pages

Linux & Unix Commands - Search Man Pages

tracertstats(1) [debian man page]

TRACERTSTATS(1) 						   User Commands						   TRACERTSTATS(1)

NAME
tracertstats - perform simple filter based analysis on a trace SYNOPSIS
tracertstats [ -f | --filter bpf ] [ -i | --interval interval ] [ -c | --count count ] [ -o | --output-format csv,txt,png,html ] [ -m | --merge-inputs ] inputuri... tracertstats -H|--libtrace-help DESCRPTION
tracertstats takes a list of bpf expressions and outputs the number of packets and bytes that match that expression every interval seconds, or count packets. -f bpf-filter --filter bpf-filter Add another "bpf filter" -i interval --interval interval Output results every interval seconds. -c count --count count Output results every count packets. -m --merge-inputs Treats all inputs as a single input, resulting a single unified output rather than an output for each input. Works best with traces that are consecutive to create a single CSV, for instance. -o format --output-format format Selects the output format. txt Human readable text. This is the default output format which provides output easily understood by a human. This format has the disadvantage that it takes up quite a bit of horizontal space. csv Comma Seperated Values. This is suitable for further analysis in a spreadsheet, or other program. png PNG Graphic. Produces a fairly incomprehensible png graph. This relies on gdc being available at compile time. html This produces output suitable for display to a human in a webbrowser. EXAMPLES
tracertstats --filter 'host sundown' --filter 'port http' --filter 'port ftp or ftp-data' --filter 'port smtp' --filter 'tcp[tcpflags] & tcp-syn!=0' --filter 'not ip' --filter 'ether[0] & 1 == 1' --filter 'icmp[icmptype] == icmp-unreach' --output-format html erf:/traces/trace1.gz erf:/traces/trace2.gz LINKS
More details about tracertstats (and libtrace) can be found at http://www.wand.net.nz/trac/libtrace/wiki/UserDocumentation SEE ALSO
libtrace(3), tracemerge(1), tracesplit(1), tracesplit_dir(1), tracefilter(1), traceconvert(1), tracereport(1), tracepktdump(1), traceanon(1), tracesummary(1), traceconvert(1), tracereplay(1), tracediff(1), traceends(1), tracetopends(1) AUTHORS
Perry Lorier <perry@cs.waikato.ac.nz> tracertstats (libtrace) November 2006 TRACERTSTATS(1)

Check Out this Related Man Page

TRACESPLIT(1)							   User Commands						     TRACESPLIT(1)

NAME
tracesplit - split traces SYNOPSIS
tracesplit [ -f bpf | --filter=bpf] [ -c count | --count=count] [ -b bytes | --bytes=bytes] [ -i seconds | --seconds=seconds] [ -s unixtime | --starttime=unixtime] [ -e unixtime | --endtime=unixtime] [ -m maxfiles | --maxfiles=maxfiles] [ -S snaplen | --snaplen=snaplen] [ -z level | --compress-level=level] [ -Z method | --compress-type=method] inputuri [inputuri ...] outputuri DESCRIPTION
tracesplit splits the given input traces into multiple tracefiles -f bpf filter output only packets that match tcpdump style bpf filter -c count output count packets per output file. The output file will be named after the basename given in the outputuri with the packet num- ber of the first packet in this file. -b bytes output bytes bytes per file -i seconds start a new tracefile after "seconds" seconds -s unixtime don't output any packets before unixtime -e unixtime don't output any packets after unixtime -m maxfiles do not create more than "maxfiles" trace files -S snaplen Truncate packets to "snaplen" bytes long. The default is collect the entire packet. -z level Compress the data using the specified compression level, ranging from 0 to 9. Higher compression levels tend to result in better compression but require more processing power to compress. -Z compression-method Compress the data using the specified compression algorithm. Accepted methods are "gzip", "bzip2", "lzo" or "none". Default value is none unless a compression level is specified, in which case gzip will be used. EXAMPLES
create a 1MB erf trace of port 80 traffic. tracesplit -z 1 -Z gzip -f 'port 80' -b $[ 1024 * 1024 ] erf:/traces/bigtrace.gz erf:/traces/port80.gz LINKS
More details about tracesplit (and libtrace) can be found at http://www.wand.net.nz/trac/libtrace/wiki/UserDocumentation SEE ALSO
libtrace(3), tracemerge(1), tracefilter(1), traceconvert(1), tracesplit_dir(1), tracereport(1), tracertstats(1), tracestats(1), tracepkt- dump(1), traceanon(1), tracesummary(1), tracereplay(1), tracediff(1), traceends(1), tracetopends(1) AUTHORS
Perry Lorier <perry@cs.waikato.ac.nz> tracesplit (libtrace) January 2011 TRACESPLIT(1)
Man Page