LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > *BSD
User Name
Password
*BSD This forum is for the discussion of all BSD variants.
FreeBSD, OpenBSD, NetBSD, etc.

Notices


Reply
  Search this Thread
Old 03-22-2014, 02:56 AM   #16
es131245
LQ Newbie
 
Registered: Mar 2014
Posts: 19

Original Poster
Rep: Reputation: Disabled

The idea is to run script as daemon on few gateway/firewall hosts of network to make sure that none of perticilar data will appear in network (at least in open format) while some work on networks and sites will be done.
Output will be done to a screen and sql database. No roblems with that.
The only problems I've come across with is soft. For now on despire tcpdump, awk and grep are old in FreeBSD 10!
Awk http://www.linuxquestions.org/questi...-ascii-488357/
and grep is "GNU Project 2002/01/22 GREP(1)" so modern regexp like (?=abc) just don't work! In php worked but not in grep.

Looks like perl is the solution.

Last edited by es131245; 03-22-2014 at 03:02 AM.
 
Old 03-22-2014, 03:24 AM   #17
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by es131245 View Post
The idea is to run script as daemon on few gateway/firewall hosts of network to make sure that none of perticilar data will appear in network (at least in open format) while some work on networks and sites will be done.
What you should remember for next time is that, as long as you're a novice and as long as all parameters aren't clear to your audience, you should present your case in full.


Quote:
Originally Posted by es131245 View Post
The only problems I've come across with is soft. For now on despire tcpdump, awk and grep are old in FreeBSD 10!
...then you are in the wrong forum in the first place. Many applications work differently in FreeBSD and the LQ BSD forums are here https://www.linuxquestions.org/questions/%2Absd-17/ and here https://www.linuxquestions.org/quest...her-%2Anix-55/ so I'll ask the moderator to move this thread.


What you don't seem to (want to) understand is that where logging is concerned there is only one mantra: you don't know what you don't log. What this basically means is that if you get things wrong you don't get a second chance as the data already slipped through your fingers. There'll be no way to check for integrity of the message or stream, no way to perform deep packet inspection, etc, etc. Secondly, the way you've shown you're doing things, you're printing (I wouldn't call it "logging" really) a relative and interpreted subset of things (see the "-s0 -n -nn -N -p -tttt" args and ponder why).
 
Old 03-22-2014, 03:46 AM   #18
es131245
LQ Newbie
 
Registered: Mar 2014
Posts: 19

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by unSpawn View Post
...then you are in the wrong forum in the first place. Many applications work differently in FreeBSD and the LQ BSD forums are here https://www.linuxquestions.org/questions/%2Absd-17/ and here https://www.linuxquestions.org/quest...her-%2Anix-55/ so I'll ask the moderator to move this thread.
Thanks for that. I've did not know that there is such a dig difference in the first place.

Quote:
Originally Posted by unSpawn View Post
you don't know what you don't log
I do log now.
First of all i "tcpdump -w stream" write to a file and leter I experiment with "tcpdump -r stream". It just did'nt mension it here.
 
Old 03-23-2014, 03:30 AM   #19
theNbomr
LQ 5k Club
 
Registered: Aug 2005
Distribution: OpenSuse, Fedora, Redhat, Debian
Posts: 5,399
Blog Entries: 2

Rep: Reputation: 908Reputation: 908Reputation: 908Reputation: 908Reputation: 908Reputation: 908Reputation: 908Reputation: 908
Your application cannot run as a daemon if it is expected to output to the screen. By definition, a daemon process has no attached terminal/console.
 
Old 03-23-2014, 03:52 AM   #20
es131245
LQ Newbie
 
Registered: Mar 2014
Posts: 19

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by theNbomr View Post
Your application cannot run as a daemon if it is expected to output to the screen. By definition, a daemon process has no attached terminal/console.
turn off output to screen and leave output to database.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
I've found tcpdump tagged as 'Installed' in PPM, why I can't find a tcpdump command ? illidan.modeler Puppy 1 09-07-2013 07:50 AM
tcpdump shows packages even if iptables policy is set to DROP paliga Linux - Networking 7 06-05-2011 11:37 AM
Help separating a value OverlordSquishy Linux - Software 2 03-17-2009 03:24 PM
separating connections [AdultSwim] Linux - Networking 5 04-14-2007 12:48 PM
separating words cxel91a Programming 14 04-29-2003 01:05 PM

LinuxQuestions.org > Forums > Other *NIX Forums > *BSD

All times are GMT -5. The time now is 03:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration