Inspect and interpret SMB messages

Hi
I am replying to an invitation to tender from a customer. They requir a product that will be able to do deep packet inspection and extract SMB events realting to shares and files that are moved or deleted. They also want it to support directory services if possible so that it can report by username !
Oh and it needs to be able to do it at a full 10Gb and store historical data for a year.
I can't think of anything that can do this kind of thing. Sure whith a packet capture you could pick out the SMB messages but storing 10Gb/s would involve thousands of terrabytes of storegae for a years worth of data.
Any ideas on something that can do at least part of this. I was thinking about some kind of Netflow analyser.
Thanks
Pat

Personally, "deep packet inspection" and "10 Gb" bring this appliance solution to mind:
http://www.netscout.com/docs/datasheets/NetScout_ds_nGenius_InfiniStream.pdf
"Broad Storage Capabilities
Configured in a variety of rack-mounted chassis options, storage
capabilities range from 500 GB to 16 TB. Chassis options vary
from 1RU appliances to larger systems.
Interfaces and Speeds
More than two dozen models are available to accommodate
deployments across the modern IP network. Monitoring speeds
range from 10base-T, to Fast Ethernet, to high-speed 10-GbE
interfaces. Port densities are available in 2-Port, 4-Port, and
8-Port capture configurations."
So it doesn't have anywhere near the storage for a full year's worth of data, but then 16TB is the most built-in storage on any network monitoring appliance I've heard of (and apparently the price tag to match). It's also unclear whether it meets some of the other requirements, but I suppose the vendor's professional services might be able to cater to those if the customer has the budget to support those requirements.
OTOH, as you've pointed out, NetFlow is not deep-packet inspecting, but if that's "good enough" for the purpose, there's at least one hardware-based NetFlow solution capable of scaling up to 10G, http://www.invea-tech.com/products/flowmon, courtsey of this old thread: https://supportforums.cisco.com/message/653987#653987

Similar Messages

  • After aborted rebuild in Mail: I can see and select the message in the center pane and when I click on it to display, I get "Loading" text, but nothing comes up

    I have searched quite a bit to find a resolution to this problem, with no success. Any help would be appreciated.
    I decided to rebuild my inboxes by following this advice: http://support.apple.com/kb/PH11704. The rebuild took several hours and at 96% (4 minutes remaining apparently), the indexing froze (that is, after 8 hours, the message was still telling me "4 minutes left"). I forced quit mail, restored the previous Envelope files from the trash, and everything seemed fine.
    However, since this failed attempt, I can see and select the message in the center pane and when I click on it to display, I get "Loading" text, but nothing comes up. All messages in my various inboxes have the reloading problem, EXCEPT messages that I downloaded since the aborted rebuild (in other words, there are about 40 messages that I downloaded since I tried the rebuild and I have no problem with these). The other 70,000 messages however wont load, even though I can see them in the centre pane and spotlight has no problem finding them and showing me their contents (when I hover the mouse over the message). When I click on the message in spotlight, mail opens and the loading problem re-occurs.
    Since then, based on various suggestions I found for similar issues, I have used Disk Utility to verify and repair permissions and the drive. I used Onix to rebuild the Mail index (that only took about a minute - I am not sure how to interpret this when compared to the hours the rebuild took with Mail). No joy, I still have the same problem. I even restored one of my inboxes via Time Machine and the same issue with loading continues.
    I am using ML 10.8.2. I have a combination of IMAP accounts (work) and POP accounts (personal). The issue of loading occurs irrespective of the account.
    I am baffled and am now considering migrating to either Thunderbird or Postbox 3 to try and solve my problem. I prefer to stay with Mail. I should note also that I am using MailTags with Mail (http://www.indev.ca/MailTags.html), although I have not used any of the features. I upgraded to ML from SL about 2 weeks ago. It was very smooth and there appear to be no issues (not sure how helpful this is and probably not at all related to this issue).
    Any suggestions much appreciated!

    Maybe these will help:
    https://discussions.apple.com/message/17677533#17677533
    https://discussions.apple.com/message/18324129#18324129
    https://discussions.apple.com/message/18203126#18203126

  • How can I learn to interpret log messages in Console?

    I was given some instuctions on how to use Console to help solve a problem with my 24-inch Early 2009 iMac (3.06 GHz Intel Core 2 Duo, 8 GB 1067 MHz DDR3) becoming unresponsive and hanging which I solved for a while by removing Google Drive from my startup items (it was crashing).
    Now a similar problem has returned where it takes up to twenty minutes for my iMac to startup and become responsive. I returned to Console to see it I could figure out what was wrong on my own and realized I have little idea what the Console messages are telling me.
    For example I see these 3 lines repeatedly:
    4/15/15 12:02:05.658 PM configd: DHCPv6 en0: SendInformRequest transmit failed, Can't assign requested address
    4/15/15 12:02:41.941 PM ntpd: bind(31) AF_INET6 fe80::226:b0ff:fee3:5444%4#123 flags 0x11 failed: Can't assign requested address
    4/15/15 12:02:41.941 PM ntpd: unable to create socket on en0 (121) for fe80::226:b0ff:fee3:5444#123
    I have an Apple TV, 2 Kindles, and a MacBook Pro and wonder if these messages relate to Network communications between my devices or …?
    Another example:
    4/14/15 10:59:59.877 PM iTunes: Failed to create replacement string
    Does this indicate a problem or is it simple the result of turning off iTunes use of speakers connected to my Apple TV?
    Is there a reference or text somewhere that I can access to learn how to interpret Console messages?
    Thanks,
    Mike Barrett

    That article assumes you know how to obtain and install a signing certificate.
    For that, go here: http://www.thawte.com/secure-email/personal-email-certificates/index.html?click= DoYouNeedTo-SecureMail
    Once you have the certificate, you may need to open Keychain Access, and do a File -> Import on the certificate file. When finished, you should see something under "My Certificates".

  • Trying to install Illustrator CS3 on Windows 8.1 and get error message-installer database is corrupt

    When I try to install Illustrator CS3 on a windows 8.1 machine and get the following error message. " Installer database is corrupt". Have tried rebooting computer etc. and still the same problem, any suggestions?

    BrianDany I am sorry you are facing difficulties installing Creative Suite 3 under Windows 8.1.  Windows 8.1 was not available during the time period which Creative Suite 3 was developed and the last updates released.
    I would recommend reviewing your PDApp.log and possibly AMT3lib.log file for error messages which are preventing the installation.  You can find details on how to locate and interpret the log files at Troubleshoot installation with install logs | CS3, CS4.  You are welcome to post any specific error messages which you discover to this discussion.

  • In process Inspection and Rework Qty Issue

    Hi,
    There is Production Order for 100 qty.  There are 5 in process operations like 0010 Cutting, 0020 Welding, 0030 Inspection, 0040 turning, and 0050 Inspection
    (1)0010 operation is finished by production for 50 qty and confirmed through co11n by entering yield as 50 qty.
    (2)0020 operation is finished by production for 50 qty and confirmed through co11n by entering yield as 50 qty.
    (3)0030 operation: Quality inspected and entered results as 25 as yield and 25 as rework. For defects Q3 notification is
         triggered.( ie CO11N transaction is called in QM)
    (4)Production opened rework order CO07 and confirmed the rework operation and booked material and labor cost on cost
         center instead of orginal order.
    (5)0040: Operation production could confirm only 25 qty as earlier 0030 operation of inspection  yield was only 25 qty.
    (6)Inspection already in 0030 operation 25 qty  was entered as rework. Now after rework how results recording will be done 
         and qty will be posted in yield. Unless yield is entered under 0030 operation for 25 qty , production cannot confirm the 0040
         operation for pending 25qty.
    (7)Business requirement is what ever the qty production manufactures it has to be entered in system. Based on quality
         inspection incentive will be paid to only qty which is passed by quality.
    Settings Made:
    (a)100 Free Inspection, No Qty Relation, Quantity Valuation and Confirmation in Production for only inspection work center
         without any cost capturing.
    (b)Confirmation parameters settings with error for over and under delivery tolerance, error if inspection sequence not adhered,
         error message if no inspection results exists
    Any suggestion or any other way of handling this requirement.
    Thanks & Regards,
    RSR

    Hi RSR,
    Your way of mapping is absolutely fine, few points to be clear...
    03 inpection type and enable inspection characterisitics for operation 030
    04 inspeciton type to be enabled and operation 050 shall be eliminated if possible, material stock posting will be done from 04 inspection lot for 25 nos.
    let me know if you have questions..
    regards,
    Lenin. A

  • Tracing execution and standard Forte message filters

    Hello,
    During the process of tuning an application, or just of making it work, it
    is useful to trace the flow of processing.
    There are two ways of doing it :
    1) add your own trace instructions (calls to the LogMgr) at the appropriate
    places,
    2) use the traces of the Forte Interpreter !
    If one relies on solution 1, then it relies on what the developers have
    written (and thus sometime forgotten to write !) in their code.
    If one relies on solution 2, then potentially it can get as much information
    as is available to the interpreter (and the debugger ?), in a fully
    independant way since it uses directly the code itself and not added trace
    instructions.
    So solution 2 seems quite interesting.
    Unfortunately there are some potential problems :
    a) I haven't found in the documentation an exhaustive description of the
    logs the Forte tools do. The only and very short description is on page 148
    of the System management Guide. It's far from being exhaustive. So it
    requires playing with the filters.
    I recommand trying trc:in:1-63. I guess "in" stands for the interpreter.
    - level 1 seems to give the call tree,
    - level 255 seems to give almost the code !
    b) since the flags are not documented by Forte, how reliable and stable will
    they be in future versions ?
    c) what happens for compiled partitions is not clear to me (I have not tried
    it yet).
    So my question : are the message filters used by the Forte Tools like the
    interpreter described somewhere, i.e. in some Tech Note (I don't have access
    to them yet) ?
    best regards,
    Pierre Gelli
    ADP GSI
    Payroll and Human Resources Management
    72-78, Grande Rue, F-92310 SEVRES
    phone : +33 1 41 14 86 42 (direct) +33 1 41 14 85 00 (reception desk)
    fax : +33 1 41 14 85 99

    From: Pierre Gelli <[email protected]>
    Subject: tracing execution and standard Forte message filters
    Hello,
    During the process of tuning an application, or just of making it work, it
    is useful to trace the flow of processing.
    There are two ways of doing it :
    1) add your own trace instructions (calls to the LogMgr) at the appropriate
    places,
    2) use the traces of the Forte Interpreter !
    So solution 2 seems quite interesting.
    Unfortunately there are some potential problems :
    a) I haven't found in the documentation an exhaustive description of the
    logs the Forte tools do. The only and very short description is on page 148
    of the System management Guide. It's far from being exhaustive. So it
    requires playing with the filters.
    I recommand trying trc:in:1-63. I guess "in" stands for the interpreter.
    - level 1 seems to give the call tree,
    - level 255 seems to give almost the code !
    b) since the flags are not documented by Forte, how reliable and stable will
    they be in future versions ?
    Pierre Gelli,
    level 255 is the most detailed you are right on tracing..... As for documentation
    you will want to get ahold of several good tech notes that your Forte
    rep or support can get you which provide alot of the info you are after.
    Let me know if you can't do this and I can send you some of this info, but you are
    best to get the latest and greatest directly from Forte.
    Len Leber
    ATG Partners

  • QE573 and QE570 error messages always getting printed while releasing orders from COR5 T-Code.

    Hi Experts,
    User is getting QE573 and QE570 printed messages while releasing every process order from COR5 T-Code.
    I tried to investigate this and found that these are printing messages for "Sample Drawing Instruction" and "Inspection instruction", and there is a print setting in CB85 because of which these message are printed.
    But need to know if there is any additional setting related to Production Planning/Order Types/Plants because of which these printed messages are appearing in COR5 T-Code.
    If yes, then please mention the settings and possible how to resolve this so that the users don't get this while releasing any order.
    Thanks
    Adarsh

    Hi Ajay,
    In KEPC with the combination of sales organisation &, billing type  costing key is assigned for the valuation class 7010 (Finished goods) But costing key is not assigned to valuation class 3000 (raw material). and I saw the same setting in quality. Still we are able to create the acounting document. But in case of production it is asking for cost estimate with the costing keys for the valuation class 7010.. Is any other setting which is missing in Quality as we are able to create accounting documents though the costing key is defined for the valuation class 7010. 
    Can you please advise?
    Thanks & Regards
    Veda

  • 'Hello' does not want to compile and interpret

    I recently downloaded the latest JDK Update 12 from the sun website.
    I typed the basic hello program. The problem is in the compiling and interpreting of the program. In the command prompt, I made a new directory(folder) titled javacoding; in which I also saved the source code for the hello world program. After which i switched to it and I set the path of bin containing the compiler and interpreter to this directory. I typed in the following; javac Hello.java.
    I set the path thus: C:\javacoding> set path =%path%;C:\Program Files\Java\jdk1.6.0_11\bin;.;
    However, the program does not compile and the following message is displayed instead:
    'javac' is not recognized as an internal or external command, operable program or batch file.
    Here is a sample of the program I typed
    class Hello
    /*This program displays Hello*/
    public static void main (String args[])
    //This is the main method
    System.out.println("Hello, World!");
    For the record this was done on a Vista system.
    Thank you.

    Melanie_Green wrote:
    Variable ___________ Value
    Path ______________ C:\Program Files\Java\jdk1.6.0_11\bin;
    // Set this for both user and system variable*@Mel:* Ummm. Not to be too rude, but I'm almost certain that's incorrect, or atleast sub-optimal.
    Presuming that the OP (that's you Ikenna) is a system administrator on there own box, then just set the system PATH... all users will pick it up from there... also setting at the user-level just appends a useless duplicate entry to the PATH, slowing down (unsucessful) path-searches... not that you'd notice.
    *@OP:* Show us a dir of your jdk-bin directory... we'll need the exact command and it's output (at least down to javac.exe)... Question is: Is that directory exactly what's in your PATH? so also show us the command and output of echo %PATH% ... just post the whole command session (typos and all) between a pair of &#123;code} tags.
    Cheers. Keith.

  • I cannot open iCal because of a problem. Can anybody help me? The computer will not allow it to open and sends a message to apple each time. The icon has gone from the dock, but ical works on my iPad and I am afraid to sync it with my computer.?

    I cannot open iCal because of a problem. Can anybody help me? The computer will not allow it to open and sends a message to apple each time. The icon has gone from the dock, but ical works on my iPad and I am afraid to sync it with my computer in case it wipes everything .

    I have the exact same problem. I have not changed anything. This is probably a bug or something that has gone bad with Mac OS X (10.7.2). I have not found any solution for this on the web.
    MacBook Pro, Mac OS X (10.7.2).

  • TS3147 After installing Mountain Lion, I tried to scan from my Canon MX870 and received the message: "MP Navigator EX quit unexpectedly. Click Reopen to open the application again. A report will be sent to Apple,"

    After installing Mountain Lion, I tried to scan from my Canon MX870 and received the message: "MP Navigator EX quit unexpectedly. Click Reopen to open the application again. A report will be sent to Apple,"  This problem happened right after I installed Mountain Lion. I then downloaded Canon's upgraded software and drivers for the MX 870 and the problem was resolved. Now one month later, the problem has returned.

    rjliii wrote:
    Solved problem with original Canon software.  When I downloaded Canon software upgraded for OS X 10.8, I got all by Navigator Ex. Noticed that on Canon's site, the upgraded version is 3.1; my app was 2.1. Upgraded to 3.1 for Nav. Ex, and it works.
    You should still use Image Capture IMHO.  If it was my gear, that's what I would do.  No need to worry about software upgrades.

  • Laptop (Running Windows 8.1) no longer able to print and now see message Active Directory Domain Services is not available

    Have a very recent Lenovo Ideapad Laptop running Windows 8.1. Connected via USB port to HP LaserJet Pro CM1415 frw Color MFP Printer. Was able to print fine nearly 2 weeks ago, but something recently happened - either a new windows or office 2013 update
    or perhaps I blew away a certain file by mistake. I can see the printer installed but cannot print to it from anything (Word, Notepad, IE, Firefox etc.). The one thing to note is that usually when I plug or unplug a USB related device, Windows 8.1 recognizes
    this and makes a certain chime noise, but with the printer USB cable it never makes that noise - making me think that it never fully recognizes the printer. Also when I select the printer (from within the control panel) and right click for properties (via
    admin rights) It never lets me fully connect to it.
    I have tried all the usual remedies - remove, install all drivers, reinstall printer, Windows update, start/stop print spooler and all other printer related services,  etc. Its really annoying because this printer was working fine nearly 2
    weeks ago. Looking for any advice now. Thanks.
    -Chris

    Hi Chris,
    à
    I have tried all the usual remedies - remove, install all drivers, reinstall printer, Windows update, start/stop print spooler and all other printer related services, etc.
    I noticed that you had reinstalled the printer. Just a confirmation, when un-install this printer, please check
    if this printer still exist in registry. For more details, please refer to following KB.
    Registry entries for printing
    If printer entry still exist in registry, please delete that printer entry and re-install this printer again,
    then check if this issue still exists. (Please backup registry entries before operating registry. It will help us to avoid unexpected issue.)
    àand now see
    message Active Directory Domain Services is not available
    By the way, would you please let me know where/when get this
    Active Directory Domain Services is not available error message? Or provide a screenshot of it?
    (Please hide all protected or private information) Please check if all services are running correctly on the computer. Meanwhile, please refer to following article and check if can help you.
    Printer
    Problem: Active Directory Domain Services is currently unavailable – Why does windows say no printers are installed?
    Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft
    does not guarantee the accuracy of this information.
    If any update, please feel free to let me know.
    Hope this helps.
    Best regards,
    Justin Gu

  • The hard disc of my laptop has crashed and i lost all the data. Now I want to take back up of my I phone and transfer contacts , messages and music back into my laptop , how can I do that. Pl help

    The hard disc of my laptop has crashed and i lost all the data. Now I want to take back up of my I phone and transfer contacts , messages and music etc back into my laptop , how can I do that. Also let me know how I can transfer the contacts into Windows contacts from I phone. Pl help

    Your content will only be where you put it.  It has always been very basic to always maintain a backup copy of your computer.
    You can transfer itunes purchases from your iphone: File>Device>Transfer purchases.
    You can import your pics taken with the iphone as you would with any digital camera.
    You can e-mail the other pics to yourself, they will never be of the original quality.
    You can out a unique contact and calendar entry on the computer.  You should get the option to merge the data when you sync.

  • I can no longer import pictures to my ibook (OSX version 10.6.8) using iphoto 09 version 8.1.2 and now get message that file is in an unrecognizable format.  What is wrong?  Same camera as before.

    I can no longer import pictures to my ibook (OSX version 10.6.8) using iphoto 09 version 8.1.2 and now get message that file is in an unrecognizable format.  What is wrong?  Same camera as before.

    Julesvernet
    As a Test:
    Hold down the option (or alt) key and launch iPhoto. From the resulting menu select 'Create Library'
    Import a few pics into this new, blank library. Is the Problem repeated there?

  • Backing Up and Restoring the Message Store v.s. the queue

    Hello,
    We are running iPlanet 5.2 Messaging Server and need to migrate to another (duplicate) 5.2 Messaging Server. We have all the software installed and the LDAP user accounts created. Now we just need to move the existing mail from one server to the other.
    I found the Backing Up and Restoring the Message Store section in the Admin Guide says to back up and restore your data, Messaging Server provides the imsbackup and imsrestore utilities.
    However I am wondering about the Queue?
    Under <instance>/imta/queue
    What is the difference between the Message Store
    and the Queue? Can I just backup and restore the Queue using tar or cpio?
    Thanks in advance for any advice.
    Regards,
    Tim

    Hello,
    We are running iPlanet 5.2 Messaging Server and need
    to migrate to another (duplicate) 5.2 Messaging
    Server. We have all the software installed and the
    LDAP user accounts created. Now we just need to move
    the existing mail from one server to the other.
    I found the Backing Up and Restoring the Message
    Store section in the Admin Guide says to back up and
    restore your data, Messaging Server provides the
    imsbackup and imsrestore utilities.
    However I am wondering about the Queue?
    Under <instance>/imta/queue
    What is the difference between the Message Store
    and the Queue? The Message Store is where messages get delivered to, so you can read them.'
    The queue is where messages are temporarily stored, pending delivery to wherever they go.
    You can use tar, cpio, or what have you for the queue. Stop the server first. . .
    You then just restore the files to the new server. No need to restart or anything like that. Just dump the files in, and run
    imsimta cache -sync
    to tell the MTA to re-read the queue.
    Can I just backup and restore the
    Queue using tar or cpio?
    Thanks in advance for any advice.
    Regards,
    Tim

  • Tried to open a file I created in Numbers a while ago which I modified on 11/4/13 and got a message that I needed a newer version of Numbers.  When I went to the Mac App Store it shows that the new version is already installed.  Any suggestions?

    Tried to open a file I created in Numbers a while ago, which I modified on 11/4/13, and got a message that I needed a newer version of Numbers.  When I went to the Mac App Store it shows that the new version is already installed and there doesn't seem to be a way to reinstall it.  When I checked "About Numbers" on my MacBook it shows "Numbers '09 version 2.3".  Any suggestions as to how I can get the new version installed?

    Are you launching Pages from an icon in your Dock? Installing the update does not change the Dock icons & it does not remove the older versions. Go to your Applications folder & launch the new Pages from there.

Maybe you are looking for

  • Connect macbook pro with iphone 5 via bluetooth

    I have macbook pro and Iphone 5 both have bluetooth turned on. When I go in to Macbook Pro I can see my Iphone 5. When I go into my Iphone 5 it shows as discoverable and searching.....What am I doing wrong? The Macbook won't connect and sync with Iph

  • Added podcasts disappear from ipod's podcast folder, HELP!!

    I've have a G4 ipod and i updated all my Itunes ad ipod a while back and have been using the new pocast features, but when i conected to a older version of itunes on another computer my pobcast folder turned into a normal playlist and wont change bac

  • Differences between user task Macro 2.0 and user task

    Hi, All: There are two different user tasks available in Oracle BPEL process. 1. user task Macro 2.0 NS:http://services.oracle.com/bpel/task 2. user task NS:http://xmlns.oracle.com/pcbpel/taskservice/task As far as I know, the first user task has les

  • HDV to H.264 color loss

    Anyone know why when I convert HDV to H.264 Quicktime media, that the color saturation washes out significantly? This appears to happen in Compressor with whatever H.264 settings I choose, however it doesn't happen going to MPEG 4. Thanks, Russell

  • WLC 4402 + LAP-1242AG + No DHCP

    Greetings to all, I am trying to get some LAP-1242 to join a 4402 controller without using any DHCP server. Is that possible? Thank you in advance