Project

General

Profile

Actions

Feature #1710

open

Unix socket: Send output to unix socket

Added by Fanny Dwargee over 5 years ago. Updated over 2 years ago.

Status:
New
Priority:
Normal
Target version:
Effort:
medium
Difficulty:
medium
Label:

Description

A new socket UNIX command for analyzing PCAP files and sending the resulting logs to a UNIX socket instead sending it to an output directory as currently does would be great.

This way we can parse the whole log output in memory without touching disk increasing the performance analyzing PCAP files.

Cheers

Actions #1

Updated by Victor Julien over 5 years ago

  • Assignee set to Anonymous
  • Target version set to TBD

I like the idea, but I don't see the team having time for it anytime soon.

Btw, as a work around you could configure most outputs to output to unix socket. It would be a different socket than the control socket though.

Actions #2

Updated by Fanny Dwargee over 5 years ago

Victor,
How can I differentiate between logs of each pcap file?

Victor Julien wrote:

Btw, as a work around you could configure most outputs to output to unix socket. It would be a different socket than the control socket though.

Actions #3

Updated by Fanny Dwargee over 5 years ago

I see, just specifying a relative UNIX socket name as the output log file

Regards,
Fanny

Actions #4

Updated by Jason Ish over 3 years ago

  • Subject changed from New socket UNIX command for pcap files to Unix socket: Send output to unix socket
  • Effort set to medium
  • Difficulty set to medium

Edit title. Was: New socket UNIX command for pcap files

Actions #5

Updated by Andreas Herz over 2 years ago

  • Assignee set to Community Ticket
Actions

Also available in: Atom PDF