SQLFilter

SQLFilter is a plugin for OmniPeek that indexes packets and trace files into an SQLite database. The packets can then be searched using SQL queries. The matching packets are loaded directly into OmniPeek and analyzed. The packet database can also be used to build multi-tier data mining and network forensics systems.

As more companies save large quantities of network traffic to disk, tools like the WildPackets SQLFilter make it possible to search through packet data more efficiently. For network trouble shooters, this revolutionizes the job of finding packets. Not only does the SQLFilter allow users to search for packets across thousands of trace files, it also loads the resulting packets directly into OmniPeek or EtherPeek. This cuts out many of the steps usually involved in this process and dramatically shortens time to knowledge, and time to fix.

For a more indepth discussion of the SQLFilter read Packet Data Mining and Network Forensics.

This article is issued from Wikipedia - version of the Saturday, April 02, 2011. The text is available under the Creative Commons Attribution/Share Alike but additional terms may apply for the media files.