For each flow that Argus tracks there are
a set of common identifiers and metrics that are generated and reported
in each output status record. These include:
All
Flows
Identifiers Argus Source Identifier
Record Sequence Number
Argus Transaction Reference Number
Record Generation Cause Indicator
Encapsulation Type Indicator
Specific Flow Identifiers (see Argus
flow models) Metrics
Beginning Time (usec precision)
Ending Time
Connectivity Status Indicator Source
and Destination
Packet Count
Byte Count
Application Byte Count
Interpacket Arrival Times Source and Destination
minimum
maximum
mean
standard deviation
Argus
also provides protocol specific identifiers and metrics, which include:
IPv4 Based Flows
Identifiers IP Options (if set)
IP Identification (last seen ip_id)
Metrics
Source and Destination ToS/DSByte
TTL Indications
ICMP Redirect
ICMP UnReachable
ICMP TimeExceeded
IP Fragments Present
ToS Byte Changed
TTL value Changed
TCP
Based Flows
Identifiers TCP State Progression Negotiated TCP Options Source
and Destination Base
Sequence Numbers
TCP Flags Metrics TCP Window
Closure Indicator
TCP Syn to SynAck Time (uSecs)
TCP SynAck to Data Time (uSecs) Source and Destination Acknowledged
Bytes
TCP payload bytes
Retransmitted Packet Count
Last Reported Window Reset
Indicator
ECN Congestion Indicator
ESP
Based Flows
Metrics Source
and Destination Last Sequence Number
Packets Dropped