SunScreen EFS Release 3.0 Reference Manual

logdump Extensions

logdump is an extension of the standard snoop packet monitoring tool provided with the Solaris operating system. In general, any expertise in the use of snoop is directly applicable to use of logdump.

The facilities of logdump that are common to snoop are not detailed here; refer to the ssadm-logdump(1m) man page.

logdump has been extended to provide for the special additional needs of the SunScreen system. These extensions are summarized as:

logdump is also fundamentally different from snoop in the respect that it is not involved in decisions as to what is logged by SunScreen (rules and variables previously described provide this control). Rather logdump serves as a means to post-process log file content only. (snoop is often used to filter network input during the process of capture or direct display.)

SunScreen logs and snoop capture files are not interoperable.