Network Packet Parser with a PostgreSQL Connection.
Go to file
gurkenhabicht 7d351101b7 parallelized serialization with rayon 2020-05-18 16:51:48 +02:00
src parallelized serialization with rayon 2020-05-18 16:51:48 +02:00
.gitignore
Cargo.lock
Cargo.toml
README.md Update README.md 2020-05-13 16:23:42 +02:00

README.md

This is experimental

This version is a successor of the _POSIX_C_SOURCE 200809L implementation in which all of the data of a parsed pcap/pcapng file is written as a single and simple query. This is done rather fast (tested writes: 100*10^3 tcp packets in ~1.8 sec) but may be insecure.

Postgres databases have a custom maximum limit on each insert query of prepared statements. In order to solve this issue, parsed data is written in chunks. This value is initialized in the config file called parser.json as insert_max.

Currently, ethernet, IPv4 and TCP are the only network protocols handled.