The output pcap_flow will save connections into separate files.
|Connections of this protocol will be in separate files.
|What type of frame to save in the pcap file. Possible values are : ethernet, ipv4, docsis, 80211, radiotap, mpeg_ts, ppi.
|Prefix of the files created. This will need to be changed if the flow_proto is not tcp.
|Maximum stored size of packets.
|When set to yes, the packets will directly be written on the disk. This can be useful in some cases but will slow performances.
|Event containing informations about files created by the output.
This event starts when a new file is created and ends when the file is closed.
|Name of the output which generated the event.
|Filename being created.
|Number of packet bytes written to the file.
|Number of packets written to the file.
|List all the info of the first packet. The key is 'proto.field' and the value is the field value.
pom-ng/output/pcap_flow.txt · Last modified: 2020/05/26 21:59 by 127.0.0.1