Beruflich Dokumente
Kultur Dokumente
The command line interface is separated by major data service contexts and uses character strings to specify options.
Usage:
“-help” Help
Help command> lsdata -help
-help Help
==========
Usage:
-help <context>
format
------
directory display help for the -directory context
statistics display help for the -statistics context
chartdata display help for the -chartdata context
summary display help for the -events context
events display help for the -directory context
help display help for the -help context
time display help for specifing time range
devices display help for specifing devices
Alias Equivalents:
“-directory” Help
Help command> lsdata –help directory
-directory Help
===============
Usage:
Alias Equivalents:
Usage:
lsdata -events <type> [options] -time <start> <end> -devices "<devicespec>" "<devicespec>"..."<devicespec>"
-events <type>
format
------
Syslog Syslog {mmm dd HHmmss [Device] Event}
SyslogEx Syslog Extended {yyyy/mm/dd HHmmss.sss [Device] Event}
SyslogEid Syslog Extended {yyyy/mm/dd HHmmss.sss [EID] [Device] Event}
SyslogCsv csv {yyyymmddHHmmss.sss,EID,DeviceIP,SeverityLevel,PayLoad}
SyslogCsvUtc csv {MillisecondUTC,EID,DeviceIP,SeverityLevel,PayLoad}
ParsedCsv csv parsed data
[options]
-c <connect-string> "srv=<servername[:port]>"
-loadquery <f> Load the specified query file "f" as the input criteria
-gmt Input times are to be expressed in GMT, default is localtime
-gmtOutput Output times are to be expressed in GMT, default is localtime
format
------
[[<site>:]<deviceset>:]<device>[<eventspec>]
Alias Equivalents:
-statistics Help
================
Usage:
-statistics <type>
format
------
totalsOnly display total count and size information (default value)
byType display statistics information by event types
byDevice display statistics information by event types
byNicCategory display statistics information by nic category
byEventCategory display statistics information by event category
[options]
-c <connect-string> "host=<hostname[:port]>"
-loadquery <f> Load the specified query file "f" as the input criteria
-gmt Input times are to be expressed in GMT, default is localtime
-verbose display execution time information etc(stderr)
format
------
[[<site>:]<deviceset>:]<device>[<eventspec>]
Alias Equivalents:
-chartdata Help
================
Usage:
-chartdata <type>
format
------
byType display chartdata information by event types
byDevice display chartdata information by event types
byNicCategory display chartdata information by nic category
byEventCategory display chartdata information by event category
[options]
-c <connect-string> "host=<hostname[:port]>"
-loadquery <f> Load the specified query file "f" as the input criteria
-gmt Input times are to be expressed in GMT, default is localtime
-csv Format output in csv instead of readable format
-verbose display execution time information etc(stderr)
format
------
[[<site>:]<deviceset>:]<device>[<eventspec>]
Alias Equivalents:
none
-summary Help
================
Usage:
lsdata -summary <type> [options] -time <start> <end> -devices "<devicespec>" "<devicespec>"..."<devicespec>"
-summary <type>
format
------
ALLSUMMARY
ACCTPORTSUM
ACCTIPSUM
BYTESUM
SECIPSUM
SECPORTSUM
URLTRACSUM
SUMBYTES
SUMCONNADDR
SUMCONNPORT
SUMHTTP
SUMCOUNT
WINSUM
CATCOUNT
GENCONNADDR
GENCONNPORT
GENCONNHTTP
[options]
-c <connect-string> "srv=<servername[:port]>"
-loadquery <f> Load the specified query file "f" as the input criteria
-gmt Input times are to be expressed in GMT, default is localtime
-dns Enables DNS resolution
-suppressOutput Suppresses Output. Used for performance testing (-x for short)
-verbose display execution time information etc(stderr)
format
------
[[<site>:]<deviceset>:]<device>[<eventspec>]
Alias Equivalents:
“-time” Help
Help command> lsdata –help time
-time Help
==========
format
------
YYYYMMDD starting time to the day
YYYYMMDDhh starting time to the hour
YYYYMMDDhhmm starting time to the minute
YYYYMMDDhhmmss starting time to the second
YYYYMMDDhhmmss.sss starting time to the millisecond
now starting time is now
hour starting time is the current hour
day starting time is the current day
month starting time is the current month
start starting time is the start of existing data
format
------
YYYYMMDD ending time to the day
YYYYMMDDhh ending time to the hour
YYYYMMDDhhmm ending time to the minute
YYYYMMDDhhmmss ending time to the second
continuous ending time is infinity
now ending time is now
hour ending time is one hour beyond the starting time
day ending time is one day beyond the starting time
month ending time is end of month beyond the starting time
end ending time is the end of existing data
-devices Help
=============
format
------
[<site>:][<deviceset>:]<device>[<eventspec>]
<devicespec> examples
---------------------
ciscopix,netscreen,ds1:* All ciscopix,netscreen, and all devices in the ds1
deviceset
ds1:ciscopix,ds2:ip3 IP with DeviceSet name
ip1(et1|et2),ds2:ciscopix(et4|et5) IP with event type criteria
ciscopix|ds2:ip2|ip3(et1|et2),toplayer(et4|et5) IP with event type criteria