- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: nettladm to capture data on single port
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-30-2005 10:42 AM
тАО09-30-2005 10:42 AM
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-30-2005 08:45 PM
тАО09-30-2005 08:45 PM
Re: nettladm to capture data on single port
to collect data transmitted across specific port, you need to start tracing on data across that port. to do so :
first: start the nettladm, then choose traceing subsystem from the list menu.
select the appropriate subsystem (NS_LS_TCP or NS_LS_UDP)from the subsystems listed. from the action menu choose modify tracing.
in the modify tracing set the "Include in Tracing" to "yes", check the "Incomming Protocol Data Unit" and "Outgoing Protocol Data Unit" as appropriate.
in the "Specify Filter (Optional)" specify your source/destination ip/port. then click on "ok"
After that you have to start the configured tracing from the Action menu.
Note: * You can control the trace file size & location from "Modify Startup Parameters" in the Action Menu.
** To create a report from the collected data use Create report from File menu.
*** to stop tracing, choose stop tracing from Action menu. and toggle the "Include in Trace" to No in "Modify tracing"
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-03-2005 04:41 AM
тАО10-03-2005 04:41 AM
Solutiontcpdump -i
and later post-process the file via:
tcpdump -r
and/or use any of the tools that know how to read a tcpdump trace.
Another consideration, albeit with at least as much overhead if not possibly more, is to use tusc to system call trace the specific application - that will of course not give you the TCP/IP/Ethernet headers, but you can still see the application data, and get some idea of what the application does with the data.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-03-2005 05:12 AM
тАО10-03-2005 05:12 AM
Re: nettladm to capture data on single port
I have just started using Snort on HP-UX and find it to be a great and easy tool to use. You can get Snort (and also download pcre-6.2) from the HP-UX porting and archiving center. You will also need libpcap. The install takes less than a minute for all 3. Then you can simply do:
snort -vde port 26204
You can also pipe that into a file. Snort has many powerful features that you might find useful. Here are the links to the 3 downloads:
snort:
http://hpux.cs.utah.edu/hppd/hpux/Networking/Admin/snort-2.3.3/
pcre:
http://hpux.cs.utah.edu/hppd/hpux/Languages/pcre-6.2/
libpcap:
http://hpux.cs.utah.edu/hppd/hpux/Networking/Admin/libpcap-0.9.3/
HTH
-Hazem
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-04-2005 07:48 AM
тАО10-04-2005 07:48 AM
Re: nettladm to capture data on single port
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-04-2005 07:51 AM
тАО10-04-2005 07:51 AM
Re: nettladm to capture data on single port
If you haven't done so already, getting started on an OS upgrade might not be a bad idea. If you can jump all the way up to 11.23 (11iv2) that would be best, but going to 11.11 (11iv1) would be better than nothing.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-04-2005 03:36 PM
тАО10-04-2005 03:36 PM
Re: nettladm to capture data on single port
www.tcpdump.org
www.ethereal.com
-Arun
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-04-2005 06:05 PM
тАО10-04-2005 06:05 PM
Re: nettladm to capture data on single port
HP-UX IPFilter. Takes 10 seconds to configure
it for the logging you want. If you are using
HP-UX 11i v2, it would be already installed
on your system.
- Biswajit
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-05-2005 08:10 AM
тАО10-05-2005 08:10 AM
Re: nettladm to capture data on single port
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-05-2005 08:13 AM
тАО10-05-2005 08:13 AM