Viewing flow records as text

We can view SiLK records using the rwcut tool:

The --num-rec switch allows us to view only a specific set of records, which in our case is the first five. Again, we have a variety of options with the rwcut tool as well. We can define the fields using the --fields switch, as follows:

The output from the SiLK set of tools is very flexible and can be delimited using the --delimited switch, as follows:

We can see that ...

Get Hands-On Network Forensics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.