TRACERTSTATS(1) | User Commands | TRACERTSTATS(1) |
tracertstats - perform simple filter based analysis on a trace
tracertstats [ -f | --filter bpf ] [ -i | --interval interval ] [ -c | --count count ] [ -o | --output-format csv,txt,png,html ] [ -m | --merge-inputs ] inputuri...
tracertstats -H|--libtrace-help
tracertstats takes a list of bpf expressions and outputs the number of packets and bytes that match that expression every interval seconds, or count packets.
tracertstats --filter 'host sundown' \ --filter 'port http' \ --filter 'port ftp or ftp-data' \ --filter 'port smtp' \ --filter 'tcp[tcpflags] & tcp-syn!=0' \ --filter 'not ip' \ --filter 'ether[0] & 1 == 1' \ --filter 'icmp[icmptype] == icmp-unreach' \ --output-format html erf:/traces/trace1.gz \ erf:/traces/trace2.gz
More details about tracertstats (and libtrace) can be found at http://www.wand.net.nz/trac/libtrace/wiki/UserDocumentation
libtrace(3), tracemerge(1), tracesplit(1), tracesplit_dir(1), tracefilter(1), traceconvert(1), tracereport(1), tracepktdump(1), traceanon(1), tracesummary(1), traceconvert(1), tracereplay(1), tracediff(1), traceends(1), tracetopends(1)
Perry Lorier <perry@cs.waikato.ac.nz>
November 2006 | tracertstats (libtrace) |