Project

General

Profile

Actions

Feature #1710

open
FD CT

unix-socket: Send output to unix socket

Feature #1710: unix-socket: Send output to unix socket

Added by Fanny Dwargee about 10 years ago. Updated 5 months ago.

Status:
New
Priority:
Normal
Target version:
Effort:
medium
Difficulty:
medium
Label:

Description

A new socket UNIX command for analyzing PCAP files and sending the resulting logs to a UNIX socket instead sending it to an output directory as currently does would be great.

This way we can parse the whole log output in memory without touching disk increasing the performance analyzing PCAP files.

Cheers

VJ Updated by Victor Julien about 10 years ago Actions #1

  • Assignee set to Anonymous
  • Target version set to TBD

I like the idea, but I don't see the team having time for it anytime soon.

Btw, as a work around you could configure most outputs to output to unix socket. It would be a different socket than the control socket though.

FD Updated by Fanny Dwargee about 10 years ago Actions #2

Victor,
How can I differentiate between logs of each pcap file?

Victor Julien wrote:

Btw, as a work around you could configure most outputs to output to unix socket. It would be a different socket than the control socket though.

FD Updated by Fanny Dwargee about 10 years ago Actions #3

I see, just specifying a relative UNIX socket name as the output log file

Regards,
Fanny

JI Updated by Jason Ish almost 8 years ago Actions #4

  • Subject changed from New socket UNIX command for pcap files to Unix socket: Send output to unix socket
  • Effort set to medium
  • Difficulty set to medium

Edit title. Was: New socket UNIX command for pcap files

AH Updated by Andreas Herz about 7 years ago Actions #5

  • Assignee set to Community Ticket

VJ Updated by Victor Julien 5 months ago Actions #6

  • Subject changed from Unix socket: Send output to unix socket to unix-socket: Send output to unix socket
Actions

Also available in: PDF Atom