Flow statistic

Hi there,

Regarding flow statistic, you can do -

bro -r whatever.pcap tcp udp icmp conn

It will generate the connection summaries for you which is pretty close to what flow means. If you want to generate further statistic, you can use ipsumdump + ipaggcreate.

Or if you are looking for something exactly like you have mentioned, take a look at argus -

http://qosient.com/argus

Sometimes we really need right tool for the right job.