metron学习2

查询筛选工具

此工具公开了两种通过命令行工具过滤PCAP数据的方法:

  • 固定过滤器
  • 恒星查询语言

该工具通过执行 ${metron_home}/bin/pcap_query.sh [fixed|query]

用法

usage: Fixed filter options

 -bop,--base_output_path <arg>   Query result output path. Default is

                                 '/tmp'

 -bp,--base_path <arg>           Base PCAP data path. Default is

                                 '/apps/metron/pcap'

 -da,--ip_dst_addr <arg>         Destination IP address

 -df,--date_format <arg>         Date format to use for parsing start_time

                                 and end_time. Default is to use time in

                                 millis since the epoch.

 -dp,--ip_dst_port <arg>         Destination port

 -et,--end_time <arg>            Packet end time range. Default is current

                                 system time.

 -h,--help                       Display help

 -ir,--include_reverse           Indicates if filter should check swapped

                                 src/dest addresses and IPs

 -p,--protocol <arg>             IP Protocol

 -sa,--ip_src_addr <arg>         Source IP address

 -sp,--ip_src_port <arg>         Source port

 -st,--start_time <arg>          (required) Packet start time range.

 

usage: Query filter options

 -bop,--base_output_path <arg>   Query result output path. Default is

                                 '/tmp'

 -bp,--base_path <arg>           Base PCAP data path. Default is

                                 '/apps/metron/pcap'

 -df,--date_format <arg>         Date format to use for parsing start_time

                                 and end_time. Default is to use time in

                                 millis since the epoch.

 -et,--end_time <arg>            Packet end time range. Default is current

                                 system time.

 -h,--help                       Display help

 -q,--query <arg>                Query string to use as a filter

 -st,--start_time <arg>          (required) Packet start time range.

  • 1
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值