- Timestamp:
- Jan 15, 2010, 8:21:06 AM (16 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/samba-3.3.x/docs/manpages/vfs_smb_traffic_analyzer.8
r342 r368 1 1 2 .\" Title: smb_traffic_analyzer 2 3 .\" Author: [see the "AUTHOR" section] 3 .\" Generator: DocBook XSL Stylesheets v1.7 4.0<http://docbook.sf.net/>4 .\" Date: 10/12/20094 .\" Generator: DocBook XSL Stylesheets v1.7 <http://docbook.sf.net/> 5 .\" Date: 5 6 .\" Manual: System Administration tools 6 7 .\" Source: Samba 3.3 7 8 .\" Language: English 8 9 .\" 9 .TH "SMB_TRAFFIC_ANALYZER" "8" "10/12/2009" "Samba 3\&.3" "System Administration tools" 10 .\" ----------------------------------------------------------------- 11 .\" * (re)Define some macros 12 .\" ----------------------------------------------------------------- 13 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 14 .\" toupper - uppercase a string (locale-aware) 15 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 16 .de toupper 17 .tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ 18 \\$* 19 .tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz 20 .. 21 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 22 .\" SH-xref - format a cross-reference to an SH section 23 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 24 .de SH-xref 25 .ie n \{\ 26 .\} 27 .toupper \\$* 28 .el \{\ 29 \\$* 30 .\} 31 .. 32 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 33 .\" SH - level-one heading that works better for non-TTY output 34 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 35 .de1 SH 36 .\" put an extra blank line of space above the head in non-TTY output 37 .if t \{\ 38 .sp 1 39 .\} 40 .sp \\n[PD]u 41 .nr an-level 1 42 .set-an-margin 43 .nr an-prevailing-indent \\n[IN] 44 .fi 45 .in \\n[an-margin]u 46 .ti 0 47 .HTML-TAG ".NH \\n[an-level]" 48 .it 1 an-trap 49 .nr an-no-space-flag 1 50 .nr an-break-flag 1 51 \." make the size of the head bigger 52 .ps +3 53 .ft B 54 .ne (2v + 1u) 55 .ie n \{\ 56 .\" if n (TTY output), use uppercase 57 .toupper \\$* 58 .\} 59 .el \{\ 60 .nr an-break-flag 0 61 .\" if not n (not TTY), use normal case (not uppercase) 62 \\$1 63 .in \\n[an-margin]u 64 .ti 0 65 .\" if not n (not TTY), put a border/line under subheading 66 .sp -.6 67 \l'\n(.lu' 68 .\} 69 .. 70 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 71 .\" SS - level-two heading that works better for non-TTY output 72 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 73 .de1 SS 74 .sp \\n[PD]u 75 .nr an-level 1 76 .set-an-margin 77 .nr an-prevailing-indent \\n[IN] 78 .fi 79 .in \\n[IN]u 80 .ti \\n[SN]u 81 .it 1 an-trap 82 .nr an-no-space-flag 1 83 .nr an-break-flag 1 84 .ps \\n[PS-SS]u 85 \." make the size of the head bigger 86 .ps +2 87 .ft B 88 .ne (2v + 1u) 89 .if \\n[.$] \&\\$* 90 .. 91 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 92 .\" BB/BE - put background/screen (filled box) around block of text 93 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 94 .de BB 95 .if t \{\ 96 .sp -.5 97 .br 98 .in +2n 99 .ll -2n 100 .gcolor red 101 .di BX 102 .\} 103 .. 104 .de EB 105 .if t \{\ 106 .if "\\$2"adjust-for-leading-newline" \{\ 107 .sp -1 108 .\} 109 .br 110 .di 111 .in 112 .ll 113 .gcolor 114 .nr BW \\n(.lu-\\n(.i 115 .nr BH \\n(dn+.5v 116 .ne \\n(BHu+.5v 117 .ie "\\$2"adjust-for-leading-newline" \{\ 118 \M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[] 119 .\} 120 .el \{\ 121 \M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[] 122 .\} 123 .in 0 124 .sp -.5v 125 .nf 126 .BX 127 .in 128 .sp .5v 129 .fi 130 .\} 131 .. 132 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 133 .\" BM/EM - put colored marker in margin next to block of text 134 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 135 .de BM 136 .if t \{\ 137 .br 138 .ll -2n 139 .gcolor red 140 .di BX 141 .\} 142 .. 143 .de EM 144 .if t \{\ 145 .br 146 .di 147 .ll 148 .gcolor 149 .nr BH \\n(dn 150 .ne \\n(BHu 151 \M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[] 152 .in 0 153 .nf 154 .BX 155 .in 156 .fi 157 .\} 158 .. 10 .TH "SMB_TRAFFIC_ANALYZER" "8" "01/14/2010" "Samba 3\&.3" "System Administration tools" 159 11 .\" ----------------------------------------------------------------- 160 12 .\" * set default formatting … … 167 19 .\" * MAIN CONTENT STARTS HERE * 168 20 .\" ----------------------------------------------------------------- 169 .SH "N ame"21 .SH "N" 170 22 vfs_smb_traffic_analyzer \- log Samba VFS read and write operations through a socket to a helper application 171 .SH "Synopsis" 172 .fam C 23 .SH "SYNOPSIS" 173 24 .HP \w'\ 'u 174 \FCvfs objects = smb_traffic_analyzer\F[] 175 .fam 25 vfs objects = smb_traffic_analyzer 176 26 .SH "DESCRIPTION" 177 27 .PP … … 181 31 .PP 182 32 The 183 \FCvfs_smb_traffic_analyzer\F[] 33 vfs_smb_traffic_analyzer 184 34 VFS module logs client write and read operations on a Samba server and sends this data over a socket to a helper program, which feeds a SQL database\&. More information on the helper programs can be obtained from the homepage of the project at: http://holger123\&.wordpress\&.com/smb\-traffic\-analyzer/ 185 35 .PP 186 \FCvfs_smb_traffic_analyzer\F[] 36 vfs_smb_traffic_analyzer 187 37 currently is aware of the following VFS operations: 188 38 .RS 4 … … 199 49 .RE 200 50 .PP 201 \FCvfs_smb_traffic_analyzer\F[] 51 vfs_smb_traffic_analyzer 202 52 sends the following data in a fixed format seperated by a comma through either an internet or a unix domain socket: 203 53 .sp … … 205 55 .RS 4 206 56 .\} 207 .fam C 208 .ps -1 209 .nf 210 .if t \{\ 211 .sp -1 212 .\} 213 .BB lightgray adjust-for-leading-newline 214 .sp -1 215 57 .nf 216 58 BYTES|USER|DOMAIN|READ/WRITE|SHARE|FILENAME|TIMESTAMP 217 59 218 .EB lightgray adjust-for-leading-newline 219 .if t \{\ 220 .sp 1 221 .\} 222 .fi 223 .fam 224 .ps +1 60 .fi 225 61 .if n \{\ 226 62 .RE … … 237 73 .IP \(bu 2.3 238 74 .\} 239 \FCBYTES\F[] 75 BYTES 240 76 \- the length in bytes of the VFS operation 241 77 .RE … … 249 85 .IP \(bu 2.3 250 86 .\} 251 \FCUSER\F[] 87 USER 252 88 \- the user who initiated the operation 253 89 .RE … … 261 97 .IP \(bu 2.3 262 98 .\} 263 \FCDOMAIN\F[] 99 DOMAIN 264 100 \- the domain of the user 265 101 .RE … … 273 109 .IP \(bu 2.3 274 110 .\} 275 \FCREAD/WRITE\F[] 111 READ/WRITE 276 112 \- either "W" for a write operation or "R" for read 277 113 .RE … … 285 121 .IP \(bu 2.3 286 122 .\} 287 \FCSHARE\F[] 123 SHARE 288 124 \- the name of the share on which the VFS operation occured 289 125 .RE … … 297 133 .IP \(bu 2.3 298 134 .\} 299 \FCFILENAME\F[] 135 FILENAME 300 136 \- the name of the file that was used by the VFS operation 301 137 .RE … … 309 145 .IP \(bu 2.3 310 146 .\} 311 \FCTIMESTAMP\F[] 147 TIMESTAMP 312 148 \- a timestamp, formatted as "yyyy\-mm\-dd hh\-mm\-ss\&.ms" indicating when the VFS operation occured 313 149 .sp … … 348 184 .RS 4 349 185 .\} 350 .fam C 351 .ps -1 352 .nf 353 .if t \{\ 354 .sp -1 355 .\} 356 .BB lightgray adjust-for-leading-newline 357 .sp -1 358 186 .nf 359 187 \fI[example_share]\fR 360 188 \m[blue]\fBpath = /data/example\fR\m[] … … 362 190 \m[blue]\fBsmb_traffic_analyzer:mode = unix_domain_socket\fR\m[] 363 191 364 .EB lightgray adjust-for-leading-newline 365 .if t \{\ 366 .sp 1 367 .\} 368 .fi 369 .fam 370 .ps +1 192 .fi 371 193 .if n \{\ 372 194 .RE … … 378 200 .RS 4 379 201 .\} 380 .fam C 381 .ps -1 382 .nf 383 .if t \{\ 384 .sp -1 385 .\} 386 .BB lightgray adjust-for-leading-newline 387 .sp -1 388 202 .nf 389 203 \fI[example_share]\fR 390 204 \m[blue]\fBpath = /data/example\fR\m[] … … 393 207 \m[blue]\fBsmb_traffic_analyzer:port = 3491\fR\m[] 394 208 395 .EB lightgray adjust-for-leading-newline 396 .if t \{\ 397 .sp 1 398 .\} 399 .fi 400 .fam 401 .ps +1 209 .fi 402 210 .if n \{\ 403 211 .RE … … 409 217 .RS 4 410 218 .\} 411 .fam C 412 .ps -1 413 .nf 414 .if t \{\ 415 .sp -1 416 .\} 417 .BB lightgray adjust-for-leading-newline 418 .sp -1 419 219 .nf 420 220 \fI[example_share]\fR 421 221 \m[blue]\fBpath = /data/example\fR\m[] … … 425 225 \m[blue]\fBsmb_traffic_analyzer:anonymize_prefix = User\fR\m[] 426 226 427 .EB lightgray adjust-for-leading-newline 428 .if t \{\ 429 .sp 1 430 .\} 431 .fi 432 .fam 433 .ps +1 227 .fi 434 228 .if n \{\ 435 229 .RE
Note:
See TracChangeset
for help on using the changeset viewer.
