cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
914
Views
0
Helpful
3
Replies

Viewing of iplog Logs

pbobby
Level 1
Level 1

I was told in a current TAC case that to view the iplogs you can use Ethereal. Ethereal is great, but it doesn't open the iplogs.

I'm using v0.8.7 and get a "not in a recognized file format" error msg when I try to open an iplog file.

It's not tcpdump either, what should I be using to view these files?

3 Replies 3

mlhall
Level 1
Level 1

I added support for CSIDS IPLog format to ethereal starting in version 0.8.12. If you get the latest version from www.ethereal.com you should be able to read the file.

To check on changes to ethereal, you can watch http://www.ethereal.com/ChangeLog

Please let me know if you have trouble opening the log after you have upgraded to a version >= 0.8.12.

mgudell
Level 1
Level 1

If you are talking about the log files that are stored on the sensor, (log.20010426####) they are comma delimited and can be read in excel or anything that reads SDF files. If you are talking about the event database on CSPM, they are in a database format, and good luck finding something to read them.

The nice thing about ethereal is that it will parse the iplog files and do packet decode. It can also write the iplogs back out in pcap format (useful with TCPDUMP) for replay (have to hack TCPDUMP to add MAC info).

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: