AUDITING NETWORK ACTIVITY

Using Argus

Getting Argus

Argus Wiki

Development

Documentation

Publications

Support

Links

News

Argus Client Example Programs

The argus-clients package provides a set of example client programs that provide extended processng and analytics for argus flow data. These includes providing a processing environment, new processing and analytics, graphing, storage managment, forensics, and reporting tools. For these examples, we use standard sets of argus data.

raconvert

Ascii to binary data record conversion.

radark

Scanner detection and reporting.

radump

Decode captured user data buffers.

raevent

Non flow data printing.

rafilter

High performance argus record filtering.

ragraph

Time series graphing (rrd-tool based)

ragrep

Regular expression matching from captured user data.

rahisto

Frequency distribution analysis for argus data metrics.

rahosts

IP address inventory reporting

ralabel

Semantic enhancement / metadata tagging.

ramysql

Mysql based database utilities.

rapath

Print topology information derived from argus data.

rapolicy

Continuous access control policy verification.

raports

Application port usage

rarpwatch

Arpwatch application driven using argus data.

raservices

User data analysis to determine actual protocol in use.

rastream

Enhanced stream block processing.

rastrip

Argus data conditioning and compression.

ratemplate

Ra client development template for using the argus clients library.

ratimerange

Argus data file time span.

ratop

Realtime argus data processing environment (curses based)
provides vi() like functionality for streaming and file based flow data,
supporting printing, searching, editing, sorting, writing argus data.

Each of these core programs provide a basic set of features that are needed to get utility from argus based flow data.