Package argus-clients

Client tools for argus network audit

http://qosient.com/argus

Clients to the argus probe which process and display information.

General Commands (Section 1)
ra
Ra reads argus(8) data from either stdin, an argus-file, or from a remote data source, which can either be an argus-server, or a netflow data server, filters...
rabins
Rabins reads argus data from an argus-data source, and adjusts the data so that it is aligned to a set of bins, or slots, that are based on either time, input...
racluster
Racluster reads argus data from an argus-data source, and clusters/merges the records based on the flow key criteria specified either on the command line, or in...
raconvert
Raconvert reads comman separated ASCII argus data from a file or stdin, and converts the ASCII representation to binary format. In order for raconver to process...
racount
Racount reads argus data from an argus-file list, and prints out various counts from the data in the file. Racount supports, by default, a single line output...
radecode
Radecode is a perl script that uses text2pcap(1) and tshark(1) from the wireshark(1) distribution to decode TCP and UDP flow associated user data from an argus...
radump
Radump reads argus data from an argus data stream or file, and prints out tcpdump style decoding of the user data buffers.
raevent
Raevent reads argus(8) data from either stdin, an argus-file, or from a remote argus data source, filters the records it encounters based on an optional...
rafilteraddr
Rafilteraddr reads argus data from an argus-data source, and selects records that include IP addresses specified by the address.spec file. This program provides...
ragraph
Ragraph reads argus(8) data from an argus-file, and graphs fields of interest from matching argus flow activity records. You must specify the metric(s), the...
ragrep
Ragrep reads argus data from an argus-data source, greps the records based on the regexp specified on the command line, and outputs a valid argus-stream. Ragrep...
rahisto
Rahisto reads argus data from an argus-data source, sorts the records based on the criteria specified on the command line, and outputs a valid argus-stream.
ralabel
Ralabel reads argus data from an argus-data source, and selects records that include IP addresses specified by the address.spec file. This program provides high...
ranonymize
Ranonymize reads argus data from an argus-data source, strips out specific fields, and anonymizes the remaining fields in Argus records, including the network...
rapath
Rapath reads argus data from an argus-data source, and generates the path information that can be formulated from flows that experience ICMP responses. When a...
rapolicy
Rapolicy reads argus data from an argus-file list, and tests the argus data stream against a Cisco access control list configuration file Rapolicy can do many...
rasort
Rasort reads argus data from an argus-data source, sorts the records based on the criteria specified on the command line, and outputs a valid argus-stream.
rasplit
Rasplit reads argus data from an argus-data source, and splits the resulting output into consecutive sections of records based on size, count time, or flow...
rasql
Rasql reads argus data from an argus-client generated mysql database. The principal function of rasql is to extract the 'record' binary blob that is inserted by...
rasqlinsert
Rasqlinsert writes argus data into a mysql database. The principal function of rasqlinsert is to insert and update flow data attributes, into a MySQL database...
rasqltimeindex
Rasqltimeindex index argus data files by time. The principal function of rasqltimeindex is to provide fast access to indexed argus data files based on time.
rastream
Rastream reads argus data from an argus-data source, and splits the resulting output into consecutive sections of records based on size, count time, or flow...
rastrip
Rastrip reads argus data from an argus-data source, strips the records based on the criteria specified on the command line, and outputs a valid argus-stream...
ratop
Ratop reads argus(8) data from an argus-file, or from a remote data source, and periodically displays a sorted list of network flow records. When read from a...
File Formats (Section 5)
racluster
Programs that perform flexible aggregation of argus data, such as racluster(1) and radium(8), can be configured to aggregate using arbitrary flow models. This...
racolor.conf
This configuration is a color configuration file for ratop.1. It is modeled after a ralabel(1) configuration file. This configuration would be referenced in a...
radium.conf
Radium will open this radium.conf if its installed as /etc/radium.conf. It will also search for this file as radium.conf in directories specified in...
ralabel.conf
This configuration is a ralabel(1) configuration file. The concept is to provide a number of labeling strategies with configuration capabilities for each of the...
ranonymize
This configuration file provides the ability to specify options for argus data anoymization.
rarc
Ra* clients will open this file if its in the users $HOME directory, or in the $ARGUSHOME directory, and parse it to set common configuration options. All of...
System Administration (Section 8)
radium
Radium is a real-time Argus Record multiplexor that processes Argus records and Netflow records and outputs them to any number of client programs and files...