
Session/Flow Logging with Argus
Argus (www.qosient.com/argus), another session-auditing tool, has two major
components: argus and ra*. Argus is the daemon or sniffing component, and
several clients can be used for reading and displaying the Argus data.The
advantage of using Argus is that it can maintain logs for TCP, UDP, and ICMP
IP.Table 2.2 lists Argus clients and their uses.
Table 2.2 Argus Clients and Their Uses
Client Name Description Example Use
ra “Read Argus.” This is ra –r <argus_file> >
the base client from human_read.txt
which all the others are Will produce a space formatted
built. text file.
racount Used to count events racount –ar