This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
|
пакет_nfdump [2022/03/30 09:37] val |
пакет_nfdump [2024/10/02 10:38] (current) val |
||
|---|---|---|---|
| Line 6: | Line 6: | ||
| <code> | <code> | ||
| # apt install nfdump | # apt install nfdump | ||
| + | |||
| + | # man nfcapd | ||
| # cat /etc/nfdump/default.conf | # cat /etc/nfdump/default.conf | ||
| Line 21: | Line 23: | ||
| </code><code> | </code><code> | ||
| # man nfdump | # man nfdump | ||
| - | /OUTPUT FORMATS | + | /OUTPUT FORMAT |
| # nfdump -o csv -q -R /var/cache/nfdump/ | grep 192.168.X.101 | # nfdump -o csv -q -R /var/cache/nfdump/ | grep 192.168.X.101 | ||
| Line 27: | Line 29: | ||
| # nfdump -o csv -q -R /var/cache/nfdump/ 'proto tcp and src ip 192.168.X.101' | # nfdump -o csv -q -R /var/cache/nfdump/ 'proto tcp and src ip 192.168.X.101' | ||
| - | # nfdump -o csv -q -A dstip -R /var/cache/nfdump/2022/03/ 'proto tcp and dst net 192.168.X.0/24' | cut -d',' -f5,12,13 | + | # nfdump -o csv -q -A dstip -R /var/cache/nfdump/2022/03/ 'dst net 192.168.X.0/24' | cut -d',' -f5,12,13 |
| </code> | </code> | ||