CERT/CC
background
background
CERT NetSA Security Suite 
Open Source Tools for Network Monitoring 
News | Downloads | Documentation | Wiki | Tooltips
SiLK 2.1.0 | YAF 1.0.0.2 | IPA 0.4.0 | fixbuf 0.8.0 | Portal 0.9.0 | RAVE 1.9.16 | iSiLK 0.1.6

User Documentation

SiLK Handbooks:

SiLK Analysts' Handbook ( 3.5MB pdf ) is a tutorial on using SiLK for network traffic analysis.
The SiLK Reference Guide ( 1.2MB pdf ) contains the manual pages for every SiLK tool in a single document.
PySiLK: SiLK in Python ( 0.2MB pdf ) describes the Python objects that SiLK extension provides.

SiLK Tooltips:

The SiLK Tooltips site includes tips and tricks to use with the SiLK analysis suite. The tips point out very useful but less obvious features of the tools.

SiLK Analysis Tools and Plug-Ins:

addrtype(3)
ccfilter(3)
flowrate(3)
mapsid(1)
num2dot(1)
pmapfilter(3)
pysilk(3)
rwaddrcount(1)
rwappend(1)
rwbag(1)
rwbagbuild(1)
rwbagcat(1)
rwbagtool(1)
rwcat(1)
rwcompare(1)
rwcount(1)
rwcut(1)
rwdedupe(1)
rwfglob(1)
rwfileinfo(1)
rwfilter(1)
rwgeoip2ccmap(1)
rwgroup(1)
rwidsquery(1)
rwip2cc(1)
rwipaexport(1)
rwipaimport(1)
rwipfix2silk(1)
rwmatch(1)
rwnetmask(1)
rwp2yaf2silk(1)
rwpcut(1)
rwpdedupe(1)
rwpmapbuild(1)
rwpmapcat(1)
rwpmatch(1)
rwptoflow(1)
rwrandomizeip(1)
rwresolve(1)
rwscan(1)
rwscanquery(1)
rwset(1)
rwsetbuild(1)
rwsetcat(1)
rwsetintersect(1)
rwsetmember(1)
rwsettool(1)
rwsetunion(1)
rwsilk2ipfix(1)
rwsort(1)
rwsplit(1)
rwstats(1)
rwswapbytes(1)
rwtotal(1)
rwtuc(1)
rwuniq(1)
silk(7)
silk.conf(5)
silkpython(3)

iSiLK Manuals:

iSiLK User's Guide
iSiLK Development & Deployment Guide

IPA Utilities

ipaimport(1) ipaexport(1) ipaquery(1)

Administrator Documentation

NetSA Wiki:

The Administration section of the NetSA Wiki includes information on configuring YAF and SiLK, and RPMs are also available.

SiLK Handbooks:

SiLK Installation Handbook ( 1.4MB pdf ) provides extensive documentation for installing SiLK.

SiLK Packing System:

flowcap(8)
rwflowappend(8)
rwflowpack(8)
rwguess(8)
rwpackchecker(8)
rwreceiver(8)
rwsender(8)
sensor.conf(5)

YAF Flow Collector:

yaf
yafscii

RAVE Analysis Engine:

RAVE Administrator's Guide

Developer Documentation

libfixbuf API (online docs)
libipa API (online docs)
IPA Python API (online docs)
libairdbc API (online docs)