<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>Search results matching tag 'NETMON input format'</title><link>http://forums.iis.net/search/SearchResults.aspx?o=DateDescending&amp;tag=NETMON+input+format&amp;orTags=0</link><description>Search results matching tag 'NETMON input format'</description><dc:language>en-US</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>RE: Netmon 3 and new version of log parser</title><link>http://forums.iis.net/p/1145812/1854969.aspx#1854969</link><pubDate>Thu, 07 Dec 2006 14:54:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1854969</guid><dc:creator>LogParser User : Ken Vizena</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>I know the original author has left Microsoft from previous posts. I also know that there are severe problems with non-tcp data being manipulated that is not fixed with the current version (post below this one). I am working on a perl script instead of waiting for an update. </description></item><item><title>Netmon 3 and new version of log parser</title><link>http://forums.iis.net/p/1145812/1851024.aspx#1851024</link><pubDate>Tue, 05 Dec 2006 16:42:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1851024</guid><dc:creator>LogParser User : fred esnouf (ISA MVP)</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I would like to know if the team plan to release a new version of log parser especially on netmon files. I am doing a lot of network analysis, and there are some limitations ... because netmon V3 is here now, I wonder if there is a plan to update LogPArser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fred&lt;/P&gt;</description></item><item><title>libpcap =&gt; editcap =&gt; netmon v2 =&gt; log parser 2.2 =&gt; sql 2000/2005</title><link>http://forums.iis.net/p/1145831/1851043.aspx#1851043</link><pubDate>Tue, 21 Nov 2006 20:23:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1851043</guid><dc:creator>LogParser User : Ken Vizena</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>We are working on a project to place internal firewalls between very busy segement of our network. We have captured several hundred gb's worth of traffic using ethereal/wireshark. We use editcap to save the file as a netmon v2 file and then use log parser 2.2 to push the converted files into SQL 2000/2005. Once the data exists within a database we right summary reports to group the traffic by sites (several).&lt;br&gt;&lt;br&gt;Example (not checked for this post)- &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt;&lt;br&gt;&lt;br&gt;site01: lt-tcp/1023 &lt;=&gt; site02: gt-tcp/1023&lt;br&gt;site01: gt-tcp/1023 &lt;=&gt; site02: lt-tcp/1023&lt;br&gt;site01: gt-tcp/1023 &lt;=&gt; site02: gt-tcp/1023&lt;br&gt;site01: lt-tcp/1023 &lt;=&gt; site02: lt-tcp/1023&lt;br&gt;site01: lt-tcp/1023 &lt;=&gt; site02: lt-tcp/1023&lt;br&gt;site01: tcp/123 &lt;=&gt; site02: tcp/123&lt;br&gt;&lt;br&gt;gt = &gt;&lt;br&gt;lt = &lt; &lt;br&gt;&lt;br&gt;Once we have identified all permitted traffic we then write nested acl's to have sql 2005 reporting generate our acl's automagically. &lt;br&gt;&lt;br&gt;The reason I am asking this question in the forum is we have noticed that log parser does not have a protocol column. All non-tcp packets are dropped when log parser pipes the netmonv2 logs into SQL. &lt;br&gt;&lt;br&gt;Txt output from capture file that includes frame/packet number 123:&lt;br&gt;&lt;br&gt;o.     Time        Source                Destination           Protocol Info&lt;br&gt;    123 11.394410   10.10.100.1           10.10.24.101          Syslog   LOCAL4.NOTICE: %REMOVED-5-111008: User 'REMOVED' executed the 'REMOVED' command.\n&lt;br&gt;&lt;br&gt;Frame 123 (116 bytes on wire, 116 bytes captured)&lt;br&gt;Ethernet II, Src: ExtremeN_10:ef:c0 (00:01:30:10:ef:c0), Dst: HewlettP_cf:b7:5b (00:13:21:cf:b7:5b)&lt;br&gt;Internet Protocol, Src: 10.10.100.1 (10.10.100.1), Dst: 10.10.24.101 (10.10.24.101)&lt;br&gt;User Datagram Protocol, Src Port: syslog (514), Dst Port: syslog (514)&lt;br&gt;    Source port: syslog (514)&lt;br&gt;    Destination port: syslog (514)&lt;br&gt;    Length: 82&lt;br&gt;    Checksum: 0xd094 [correct]&lt;br&gt;Syslog message: LOCAL4.NOTICE: %REMOVED-5-111008: User 'REMOVED' executed the 'REMOVED' command.\n&lt;br&gt;&lt;br&gt;&lt;br&gt;Here is the exported data after doing "C:\Program Files\Log Parser 2.2&gt;logparser -i:NETMON -o:CSV "select * INTO NetMonOutput.csv from testing.cap"&lt;br&gt;&lt;br&gt;&lt;br&gt;C:\Program Files\Log Parser 2.2\testing.cap	122	11/21/2006 14:18	106	00013010EFC0	10.10.removed.removed	22	001321CFB75B	10.10.24.101	2251	4	253	AP	955091222	2910384781	8192	52	.ch.u.E{...3.....S.^.k..6x]....o...vv.o'..HR....o.N_	1&lt;br&gt;&lt;br&gt;C:\Program Files\Log Parser 2.2\testing.cap	124	11/21/2006 14:18	54	001321CFB75B	10.10.removed.removed	2251	00013010EFC0	10.10.100.1	22	4	128	A	2910384781	955091274	15732	0		1&lt;br&gt;&lt;br&gt;As you can see the logparser drops any non-tcp packets when doing the output to any format when using netmon v2 (tested v1 as well with same results)&lt;br&gt;&lt;br&gt;&lt;br&gt;Anyone? &lt;img src='images/emotions/tongue.gif' height='20' width='20' border='0' title='Tongue' align='absmiddle'&gt;</description></item><item><title>RE: are there any free conversion tools that can convert tcpdump or</title><link>http://forums.iis.net/p/1144815/1854929.aspx#1854929</link><pubDate>Tue, 21 Nov 2006 20:04:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1854929</guid><dc:creator>LogParser User : Ken Vizena</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>If you have etehreal/wireshark you can use editcap to export to netmonv1/v2. </description></item><item><title>RE: any one know netmon file format??</title><link>http://forums.iis.net/p/1145041/1854076.aspx#1854076</link><pubDate>Thu, 30 Mar 2006 22:08:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1854076</guid><dc:creator>LogParser User : svd</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;P&gt;May be this will help&lt;/P&gt;&lt;P&gt;c:\&amp;gt;logparser -h -i:NETMON&lt;/P&gt;&lt;P&gt;Input format: NETMON (NetMon capture files)&lt;BR&gt;Parses NetMon capture files&lt;/P&gt;&lt;P&gt;FROM syntax:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;lt;filename&amp;gt; [, &amp;lt;filename&amp;gt; ...]&lt;BR&gt;&amp;nbsp;Path(s) to NetMon .cap capture file(s)&lt;/P&gt;&lt;P&gt;Parameters:&lt;/P&gt;&lt;P&gt;&amp;nbsp;-fMode&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCPIP|TCPConn : Field mode; TCPIP: each record is a single&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP/IP packet; TCPConn: each record is a&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; single TCP/IP connection [default value=TCPIP]&lt;BR&gt;&amp;nbsp;-binaryFormat ASC|PRINT|HEX : Format of binary fields [default value=ASC]&lt;/P&gt;&lt;P&gt;Fields:&lt;/P&gt;&lt;P&gt;&amp;nbsp; CaptureFilename (S)&amp;nbsp;&amp;nbsp;&amp;nbsp; Frame (I)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DateTime (T)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FrameBytes (I)&lt;BR&gt;&amp;nbsp; SrcMAC (S)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SrcIP (S)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SrcPort (I)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DstMAC (S)&lt;BR&gt;&amp;nbsp; DstIP (S)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DstPort (I)&amp;nbsp;&amp;nbsp;&amp;nbsp; IPVersion (I)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TTL (I)&lt;BR&gt;&amp;nbsp; TCPFlags (S)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Seq (I)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ack (I)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WindowSize (I)&lt;BR&gt;&amp;nbsp; PayloadBytes (I)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Payload (S)&amp;nbsp;&amp;nbsp;&amp;nbsp; Connection (I)&lt;/P&gt;&lt;P&gt;Examples:&lt;/P&gt;&lt;P&gt;&amp;nbsp;Display total network traffic bytes per second:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LogParser "SELECT QUANTIZE(DateTime, 1) AS Second, SUM(FrameBytes) INTO&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DATAGRID FROM myCapture.cap GROUP BY Second"&lt;/P&gt;</description></item><item><title>I am unable to parse L2TP cap file using LogParser</title><link>http://forums.iis.net/p/1145273/1850485.aspx#1850485</link><pubDate>Sun, 04 Dec 2005 06:44:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1850485</guid><dc:creator>LogParser User : Bhushan</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;P&gt;I captured pure L2TP traffic into a cap file (pure means no IPSec stuff to encrypt). I can clearly see the L2TP packets in Netmon.&lt;/P&gt;&lt;P&gt;But I cant get the payload via LogParser.&lt;/P&gt;&lt;P&gt;My query is&lt;/P&gt;&lt;P&gt;&lt;FONT color=#111177&gt;LogParser.exe -i:NETMON -binaryFormat HEX "SELECT payload into temp.txt from&amp;nbsp; 'L2TP.cap' "&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Whats wrong with this query?&lt;/P&gt;&lt;P&gt;Even something like&lt;/P&gt;&lt;P&gt;&lt;FONT color=#111177&gt;LogParser.exe -i:NETMON -binaryFormat HEX "SELECT&amp;nbsp;* into temp.txt from&amp;nbsp; 'L2TP.cap' "&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color=#111111&gt;produces no ouput!&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description></item><item><title>Netmon parser doesn't work with all netmon files</title><link>http://forums.iis.net/p/1145220/1850432.aspx#1850432</link><pubDate>Sun, 02 Oct 2005 21:34:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1850432</guid><dc:creator>LogParser User : Neil Pike</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;P&gt;I can't get logparser to work with all capture files.&amp;nbsp; Netmon opens them fine though.&amp;nbsp; See below for the error I get.&lt;/P&gt;&lt;P&gt;logparser -i:NETMON "select top 1 * from nowork.cap"&lt;/P&gt;&lt;P&gt;Task aborted.&lt;/P&gt;&lt;P&gt;Statistics:&lt;BR&gt;-----------&lt;BR&gt;Elements processed: 0&lt;BR&gt;Elements output:&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR&gt;Execution time:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.01 seconds&lt;/P&gt;&lt;P&gt;I've attached a zip with a working and non-working file.&lt;/P&gt;&lt;P&gt;A bug to fix for 2.3 perhaps!&amp;nbsp; Fingers crossed anyway.&lt;/P&gt;</description></item><item><title>RE: are there any free conversion tools that can convert tcpdump or</title><link>http://forums.iis.net/p/1144815/1853546.aspx#1853546</link><pubDate>Fri, 23 Sep 2005 16:03:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1853546</guid><dc:creator>LogParser User : Poopyscumbucket</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>Install ethereal and go to the same directory where it's installed. There's a command line tool called mergecap and you can convert the libpcap format to either netmon1, netmon2, or any other format you wish under the following choices:&lt;br&gt;&lt;br&gt;libpcap - libpcap (tcpdump, Ethereal, etc.)&lt;br&gt;rh6_1libpcap - RedHat Linux 6.1 libpcap (tcpdump)&lt;br&gt;suse6_3libpcap - SuSE Linux 6.3 libpcap (tcpdump)&lt;br&gt;modlibpcap - modified libpcap (tcpdump)&lt;br&gt;nokialibpcap - Nokia libpcap (tcpdump)&lt;br&gt;lanalyzer - Novell LANalyzer&lt;br&gt;ngsniffer - Network Associates Sniffer (DOS-based)&lt;br&gt;snoop - Sun snoop&lt;br&gt;netmon1 - Microsoft Network Monitor 1.x&lt;br&gt;netmon2 - Microsoft Network Monitor 2.x&lt;br&gt;ngwsniffer_1_1 - Network Associates Sniffer (Windows-based) 1.1&lt;br&gt;ngwsniffer_2_0 - Network Associates Sniffer (Windows-based) 2.00x&lt;br&gt;nettl - HP-UX nettl trace&lt;br&gt;visual - Visual Networks traffic capture&lt;br&gt;5views - Accellent 5Views capture&lt;br&gt;niobserverv9 - Network Instruments Observer version 9&lt;br&gt;rf5 - Tektronix K12xx 32-bit .rf5 format</description></item><item><title>RE: any one know netmon file format??</title><link>http://forums.iis.net/p/1145041/1853152.aspx#1853152</link><pubDate>Wed, 29 Jun 2005 13:09:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1853152</guid><dc:creator>LogParser User : Gabriele Giuseppini</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>&lt;P&gt;The format is described in the Windows SDK - look at NetMon.h.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description></item><item><title>any one know netmon file format??</title><link>http://forums.iis.net/p/1145041/1850253.aspx#1850253</link><pubDate>Wed, 29 Jun 2005 04:41:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1850253</guid><dc:creator>LogParser User : dylan</dc:creator><cs:applicationKey>input_formats-51</cs:applicationKey><description>any one know netmon file format? discussion ? or other forum please mail me &lt;br&gt;at dylan_angel180@hotmail.com&lt;br&gt;&lt;br&gt;                                                               thks&lt;br&gt;                                                               dylan</description></item></channel></rss>