What does Argus data look like?
Argus is pretty lazy as to when it will print out its records. This is so Argus will have maximum cycles for packet processing, rather than data output. Argus can be easily tuned to be more timely in reporting audit events, but without that tuning, Argus could take as long as 30-120 seconds to print out a particular record, depending on the load of the Argus, the protocol and when the last packet was seen. Because of this, Argus presents an interesting time map for its data events. I’ll try to draw a graph. The Ax are Argus records in output order. The bars are the times that the data covers. The A’s on the X axis are the times when the A records are actually reported.