silk-rwflowappend-3.16.0-4.fc27.x86_64.rpm


Advertisement

Description

silk-rwflowappend - SiLK Toolset: Remote Data Storage Appending Daemon

Property Value
Distribution Fedora 27
Repository CERT Forensics Tools SiLK, IPA, Postgresql x86_64
Package name silk-rwflowappend
Package version 3.16.0
Package release 4.fc27
Package architecture x86_64
Package type rpm
Installed size 118.26 KB
Download size 79.87 KB
Official Mirror forensics.cert.org
SiLK, the System for Internet-Level Knowledge, is a collection of
traffic analysis tools developed by the CERT Network Situational
Awareness Team (CERT NetSA) to facilitate security analysis of large
networks. The SiLK tool suite supports the efficient collection,
storage and analysis of network flow data, enabling network security
analysts to rapidly query large historical traffic data sets. SiLK is
ideally suited for analyzing traffic on the backbone or border of a
large, distributed enterprise or mid-sized ISP.
The silk-rwflowappend package is used when the final storage location
of SiLK data files is on a different machine than that where the files
are created by the rwflowpack daemon (see the silk-rwflowpack
package).  rwflowappend watches a directory for SiLK data files and
appends those files to the final storage location where the SiLK
analysis tools (from the silk-analysis package) can process them.  To
move the files from rwflowpack to rwflowappend, an rwsender-rwreceiver
pair is typically used.

Alternatives

Package Version Architecture Repository
silk-rwflowappend-3.17.2-4.fc27.i686.rpm 3.17.2 i686 CERT Forensics Tools SiLK, IPA, Postgresql
silk-rwflowappend-3.17.2-4.fc27.x86_64.rpm 3.17.2 x86_64 CERT Forensics Tools SiLK, IPA, Postgresql
silk-rwflowappend-3.17.2-3.fc27.i686.rpm 3.17.2 i686 CERT Forensics Tools
silk-rwflowappend-3.17.2-3.fc27.x86_64.rpm 3.17.2 x86_64 CERT Forensics Tools
silk-rwflowappend-3.17.2-2.fc27.i686.rpm 3.17.2 i686 CERT Forensics Tools SiLK, IPA, Postgresql
silk-rwflowappend-3.17.2-2.fc27.x86_64.rpm 3.17.2 x86_64 CERT Forensics Tools SiLK, IPA, Postgresql
silk-rwflowappend-3.17.2-1.fc27.i686.rpm 3.17.2 i686 CERT Forensics Tools
silk-rwflowappend-3.17.2-1.fc27.x86_64.rpm 3.17.2 x86_64 CERT Forensics Tools
silk-rwflowappend-3.17.1-2.fc27.i686.rpm 3.17.1 i686 CERT Forensics Tools SiLK, IPA, Postgresql
silk-rwflowappend-3.17.1-2.fc27.x86_64.rpm 3.17.1 x86_64 CERT Forensics Tools SiLK, IPA, Postgresql
silk-rwflowappend-3.17.1-1.fc27.i686.rpm 3.17.1 i686 CERT Forensics Tools
silk-rwflowappend-3.17.1-1.fc27.x86_64.rpm 3.17.1 x86_64 CERT Forensics Tools
silk-rwflowappend-3.16.1-2.fc27.i686.rpm 3.16.1 i686 CERT Forensics Tools SiLK, IPA, Postgresql
silk-rwflowappend-3.16.1-2.fc27.x86_64.rpm 3.16.1 x86_64 CERT Forensics Tools SiLK, IPA, Postgresql
silk-rwflowappend-3.16.1-1.fc27.i686.rpm 3.16.1 i686 CERT Forensics Tools
silk-rwflowappend-3.16.1-1.fc27.x86_64.rpm 3.16.1 x86_64 CERT Forensics Tools
silk-rwflowappend-3.16.0-4.fc27.i686.rpm 3.16.0 i686 CERT Forensics Tools SiLK, IPA, Postgresql
silk-rwflowappend-3.16.0-3.fc27.i686.rpm 3.16.0 i686 CERT Forensics Tools
silk-rwflowappend-3.16.0-3.fc27.x86_64.rpm 3.16.0 x86_64 CERT Forensics Tools
silk-rwflowappend - - -

Requires

Name Value
libc.so.6(GLIBC_2.4)(64bit) -
libdl.so.2()(64bit) -
liblzo2.so.2()(64bit) -
libm.so.6()(64bit) -
libpthread.so.0()(64bit) -
libpthread.so.0(GLIBC_2.2.5)(64bit) -
libpthread.so.0(GLIBC_2.3.2)(64bit) -
libsilk-thrd.so.5()(64bit) -
libsilk.so.24()(64bit) -
libsnappy.so.1()(64bit) -
libz.so.1()(64bit) -
rtld(GNU_HASH) -
silk-common -

Provides

Name Value
config(silk-rwflowappend) = 3.16.0-4.fc27
silk-rwflowappend = 3.16.0-4.fc27
silk-rwflowappend(x86-64) = 3.16.0-4.fc27

Download

Type URL
Binary Package silk-rwflowappend-3.16.0-4.fc27.x86_64.rpm
Source Package silk-3.16.0-4.fc27.src.rpm

Install Howto

  1. Download cert-forensics-tools-release-27 rpm:
    https://forensics.cert.org/cert-forensics-tools-release-27.rpm
  2. Install cert-forensics-tools-release-27 rpm:
    # rpm -Uvh cert-forensics-tools-release*rpm
  3. Install silk-rwflowappend rpm package:
    # dnf --enablerepo=forensics-sip install silk-rwflowappend

Files

Path
/etc/init.d/rwflowappend
/etc/sysconfig/rwflowappend.conf
/usr/lib/.build-id/
/usr/lib/.build-id/d6/3b3f345b816bc519406c89346be05d0a3218ee
/usr/sbin/rwflowappend
/usr/share/man/man8/rwflowappend.8.gz
/var/silk/

Changelog

2017-11-09 - Lawrence Rogers <lrr@cert.org> 3.16.0-3/4
* Release 3.16.0-3/4
Rebuilt with libfixbuf 1.8.0.
2017-06-29 - Lawrence Rogers <lrr@cert.org> 3.16.0-1/2
* Release 3.16.0-1/2
rwstats
When the primary value is a distinct count, compute the number of distinct items across all bins and print each bin's percentage of the total distinct count.
Fix bugs that may occur when computing distinct counts and not all distinct counts fit into memory.
rwuniq
Fix bugs that may occur when computing distinct counts and not all distinct counts fit into memory.
flowrate plug-in
Change how the flowrate plug-in handles flow records whose duration is zero in order to fix bizarre looking output in rwstats. The plug-in now assumes each of these flow records has a duration of 400 microseconds (0.4 milliseconds).
Add the --flowrate-zero-duration switch which allows the user to set the duration that the plug-in uses for flow records whose given duration is zero.
rwrandomizeip
Read flow records from the standard input if the number of non-switch arguments is zero.
Write the flow records to the standard output if the number of non-switch arguments is zero or one.
rwswapbytes
Read flow records from the standard input if the number of non-switch arguments is zero.
Write the flow records to the standard output if the number of non-switch arguments is zero or one.
rwflowpack, flowcap
Change processing of NetFlow v9 records so that, when SiLK is compiled against libfixbuf 1.8.0, the OUT_BYTES and OUT_PKTS values are used when the IN_BYTES and IN_PKTS values are 0.
flowcap
Print the probe definitions to the log file when the log-level is set to debug.
rwflowpack, rwflowappend, flowcap, rwsender, rwreceiver, rwpollexec
Change how daemons invoke subprocesses in order to avoid creating subprocesses that deadlock and never complete.
Modify start-up scripts to be more in line with the rules in the Linux Standard Base.
Plug-ins
Add manual pages for the cutmatch, conficker-c, and app-mismatch plug-ins.
No longer install the uniq-distproto plug-in since its functionality is available as --values=distinct:protocol.

See Also

Package Description
silk-rwflowpack-3.16.0-4.fc27.x86_64.rpm SiLK Toolset: The Packer
silk-rwflowpack-3.16.1-2.fc27.x86_64.rpm SiLK Toolset: The Packer
silk-rwflowpack-3.17.1-2.fc27.x86_64.rpm SiLK Toolset: The Packer
silk-rwflowpack-3.17.2-2.fc27.x86_64.rpm SiLK Toolset: The Packer
silk-rwflowpack-3.17.2-4.fc27.x86_64.rpm SiLK Toolset: The Packer
silk-rwpollexec-3.16.0-4.fc27.x86_64.rpm SiLK Toolset: Batch Command Executor
silk-rwpollexec-3.16.1-2.fc27.x86_64.rpm SiLK Toolset: Batch Command Executor
silk-rwpollexec-3.17.1-2.fc27.x86_64.rpm SiLK Toolset: Batch Command Executor
silk-rwpollexec-3.17.2-2.fc27.x86_64.rpm SiLK Toolset: Batch Command Executor
silk-rwpollexec-3.17.2-4.fc27.x86_64.rpm SiLK Toolset: Batch Command Executor
silk-rwreceiver-3.16.0-4.fc27.x86_64.rpm SiLK Toolset: File Transfer Receiver
silk-rwreceiver-3.16.1-2.fc27.x86_64.rpm SiLK Toolset: File Transfer Receiver
silk-rwreceiver-3.17.1-2.fc27.x86_64.rpm SiLK Toolset: File Transfer Receiver
silk-rwreceiver-3.17.2-2.fc27.x86_64.rpm SiLK Toolset: File Transfer Receiver
silk-rwreceiver-3.17.2-4.fc27.x86_64.rpm SiLK Toolset: File Transfer Receiver
Advertisement
Advertisement