Comments (3)
That's not lovely :)
Could you try running stenographer with flag --v=10 and, when you run the query, paste the logs it generates in here?
from stenographer.
Ok, started a long running ping and with expanded out after and before parameters I know I have an echo/reply for every second in the time range I'm testing for.
Command:
stenoread 'icmp and after 2016-02-12T19:00:00Z and before 2016-02-12T19:02:00Z'
In this case I didn't get any packets returned. The output is attached as 190000-190200.txt. If I change the after time to 18:59, then I do get some packets in the 13:00:20 -> 13:01:19 range. That output is attached as 185900-190200.txt
185900-190200.txt
190000-190200.txt
.
from stenographer.
Okay, so making that into timestamps:
2016-02-12T19:00:00Z -> 1455303600 unix secs
2016-02-12T19:02:00Z -> 1455303720 unix secs
Looking at 190000-190200.txt, here's the files that are processed (just the ones close to the range, just thread 0):
"/tmp/stenographer720013252/PKT0/1455303017142474"
"/tmp/stenographer720013252/PKT0/1455303078263457"
"/tmp/stenographer720013252/PKT0/1455303257367202"
"/tmp/stenographer720013252/PKT0/1455303319266933"
"/tmp/stenographer720013252/PKT0/1455303380526130"
"/tmp/stenographer720013252/PKT0/1455303560343195"
"/tmp/stenographer720013252/PKT0/1455303621976087"
"/tmp/stenographer720013252/PKT0/1455303803269305"
"/tmp/stenographer720013252/PKT0/1455303864590381"
"/tmp/stenographer720013252/PKT0/1455303925700711"
Of these files we skip due to the time range (again, just those near the range, just thread 0):
"/tmp/stenographer720013252/IDX0/1455303017142474"
"/tmp/stenographer720013252/IDX0/1455303078263457"
"/tmp/stenographer720013252/IDX0/1455303257367202"
"/tmp/stenographer720013252/IDX0/1455303319266933"
"/tmp/stenographer720013252/IDX0/1455303380526130"
"/tmp/stenographer720013252/IDX0/1455303560343195" SHOULD HAVE PROCESSED
"/tmp/stenographer720013252/IDX0/1455303621976087" SHOULD HAVE PROCESSED
"/tmp/stenographer720013252/IDX0/1455303803269305"
"/tmp/stenographer720013252/IDX0/1455303864590381"
"/tmp/stenographer720013252/IDX0/1455303925700711"
Hmm, I'm somewhat stumped, but I'll look through some code.
from stenographer.
Related Issues (20)
- Ubuntu 18.04 Seccomp Failures HOT 11
- gRPC support for stenoread HOT 7
- Feature Request: Utility to dump offline stenographer sensor data to pcap HOT 4
- [Ubuntu] Stenotype keeps crashing HOT 9
- Prometheus metrics support
- Stenographer will not start on Ubuntu 16.04LTS HOT 1
- Temporary directory created before dropping privileges
- Wishlist: Community ID indexed flow extraction
- VLAN tags HOT 3
- multiple threads writing to same disk causes issues with disk cleanup HOT 10
- No such device exception seen while running install.sh on Ubuntu 18.04 HOT 1
- Export the packet through the stenoread and it will automatically break in 15 minutes HOT 1
- rpm created stenographer doesn't run HOT 3
- Notifying about index completion HOT 1
- Decapsulate ERSPAN
- Watchdog failure stenotype abort after 2 minutes (Debian 10) HOT 15
- BlockFile.AllPackets() fail when using non-standard blocksize
- Not able to set stenotype packet directory HOT 1
- Non-pretty results from output file open failure HOT 3
- PCAP-over-IP client in stenotype
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from stenographer.