offline:wrccdc_pcaps_trisulnsm
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
offline:wrccdc_pcaps_trisulnsm [2018/05/12 16:58] – veera | offline:wrccdc_pcaps_trisulnsm [2018/05/13 00:12] (current) – [Download the PCAPs] veera | ||
---|---|---|---|
Line 9: | Line 9: | ||
* [[offline: | * [[offline: | ||
* Part 2: How to use the free TrisulNSM Docker Image to analyze the PCAP dump | * Part 2: How to use the free TrisulNSM Docker Image to analyze the PCAP dump | ||
- | * Part 3: Screenshots & video of possible analysis paths (using TrisulNSM) | + | * [[offline: |
Line 18: | Line 18: | ||
- | Firstly | + | First install Docker on your host platform. We recommend Ubuntu 16.04 of CentOS 7.4. We have instructions on the [[https:// |
Line 27: | Line 27: | ||
- | Here have downloaded the first 8 files into the directory | + | Here have downloaded the first 8 files into the directory |
Line 62: | Line 62: | ||
- | A quick note on the command line options we're using | + | A quick note on the command line options we're using. For a complete list of options see [[https:// |
- | |--name | We give the instance a name of trisul1n. So it makes it easier to manipulate the system| | + | |'' |
- | |--privileged | This is needed for the '' | + | |'' |
- | | + | |'' |
- | |--webserver-port 4000 --websockets-port 4003 | We are using these two ports for web access rather than the default (3000, | + | |'' |
- | |--fine-resolution|Use 1-second timeseries data instead of the default 1-minute. We noticed that WRCCDC is very high traffic hence high-resolution timeseries is better for metrics| | + | |'' |
- | |--pcap|We use the name of the subdirectory '' | + | |
- | Upon completion | + | === Wait for completion |
+ | |||
+ | Now TrisulNSM is crunching the PCAPs. You can monitor the progress by running the following command. | ||
+ | |||
+ | < | ||
+ | docker logs -f trisul1n | ||
+ | </ | ||
+ | |||
+ | The rough time taken in our very modest system was around 40 seconds per file. When the processing finishes you will see something like this. | ||
< | < | ||
Line 90: | Line 97: | ||
+ | ==== Next ==== | ||
- | Using Trisul to analyze the PCAPs | ||
- | + | Thats it ! Now you are ready to analyze the network data using Trisul. That is [[offline:wrccdc_pcaps_results|Part 3 of this series]]. | |
- | File extraction | + | |
- | + | ||
- | < | + | |
- | DOCKER: | + | |
- | -rw-r--r-- 1 trisul trisul | + | |
- | -rw-r--r-- 1 trisul trisul | + | |
- | -rw-r--r-- 1 trisul trisul 12582912 May 11 12:52 / | + | |
- | -rw-r--r-- 1 trisul trisul 42846720 May 11 12:52 / | + | |
- | DOCKER: | + | |
- | + | ||
- | + | ||
- | </ | + | |
offline/wrccdc_pcaps_trisulnsm.1526124504.txt.gz · Last modified: 2018/05/12 16:58 by veera