<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=gb2312">
<META content="MSHTML 6.00.2900.3354" name=GENERATOR>
<STYLE>@font-face {
        font-family: 宋体;
}
@font-face {
        font-family: Verdana;
}
@font-face {
        font-family: @宋体;
}
@page Section1 {size: 595.3pt 841.9pt; margin: 72.0pt 90.0pt 72.0pt 90.0pt; layout-grid: 15.6pt; }
P.MsoNormal {
        TEXT-JUSTIFY: inter-ideograph; FONT-SIZE: 10.5pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman"; TEXT-ALIGN: justify
}
LI.MsoNormal {
        TEXT-JUSTIFY: inter-ideograph; FONT-SIZE: 10.5pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman"; TEXT-ALIGN: justify
}
DIV.MsoNormal {
        TEXT-JUSTIFY: inter-ideograph; FONT-SIZE: 10.5pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman"; TEXT-ALIGN: justify
}
A:link {
        COLOR: blue; TEXT-DECORATION: underline
}
SPAN.MsoHyperlink {
        COLOR: blue; TEXT-DECORATION: underline
}
A:visited {
        COLOR: purple; TEXT-DECORATION: underline
}
SPAN.MsoHyperlinkFollowed {
        COLOR: purple; TEXT-DECORATION: underline
}
SPAN.EmailStyle17 {
        FONT-WEIGHT: normal; COLOR: windowtext; FONT-STYLE: normal; FONT-FAMILY: Verdana; TEXT-DECORATION: none; mso-style-type: personal-compose
}
DIV.Section1 {
        page: Section1
}
UNKNOWN {
        FONT-SIZE: 10pt
}
BLOCKQUOTE {
        MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px; MARGIN-LEFT: 2em
}
OL {
        MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px
}
UL {
        MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px
}
</STYLE>
</HEAD>
<BODY style="FONT-SIZE: 10pt; MARGIN: 10px; FONT-FAMILY: verdana">
<DIV><FONT face=Verdana color=#000080 size=2>系统:linux&nbsp;&nbsp; 
perl版本:5.8</FONT></DIV>
<DIV>目的:</DIV>
<DIV>想使用perl来实时抓取tcpdump数据,并统计10分钟的流量。</DIV>
<DIV>&nbsp;</DIV>
<DIV>我的代码片段如下:</DIV>
<DIV>
<DIV><FONT color=#3366ff>#!/usr/bin/perl&nbsp;-w</FONT></DIV>
<DIV><FONT color=#3366ff></FONT>&nbsp;</DIV>
<DIV><FONT color=#3366ff>#got system time now</FONT></DIV>
<DIV><FONT color=#3366ff>my&nbsp;$time_now;</FONT></DIV>
<DIV>
<DIV><FONT color=#3366ff>my&nbsp;$time_temp&nbsp;=&nbsp;`date`;</FONT></DIV>
<DIV><FONT 
color=#3366ff>if&nbsp;($time_temp&nbsp;=~&nbsp;/(\d\d):(\d\d):(\d\d)/){</FONT></DIV>
<DIV><FONT 
color=#3366ff>&nbsp;&nbsp;$time_now&nbsp;=&nbsp;($1*60*60)&nbsp;+&nbsp;($2*60)&nbsp;+&nbsp;$3;</FONT></DIV>
<DIV><FONT color=#3366ff>}</FONT></DIV>
<DIV><FONT color=#3366ff></FONT>&nbsp;</DIV>
<DIV><FONT color=#3366ff>#got tcpdump data</FONT></DIV></DIV>
<DIV><FONT 
color=#3366ff>chomp(my&nbsp;@data&nbsp;=&nbsp;`tcpdump&nbsp;-i&nbsp;eth0&nbsp;-nnn`);</FONT></DIV>
<DIV>
<DIV><FONT color=#3366ff></FONT></DIV><FONT 
color=#3366ff>print&nbsp;$time_now;</FONT></DIV>
<DIV><FONT color=#3366ff></FONT></DIV>
<DIV><FONT color=#3366ff>foreach&nbsp;my&nbsp;$data(@data){</FONT></DIV>
<DIV><FONT color=#3366ff>&nbsp;&nbsp;print&nbsp;$data;</FONT></DIV>
<DIV><FONT color=#3366ff>}</FONT></DIV></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=Verdana color=#000080 size=2>遇到的问题:</FONT></DIV>
<DIV><FONT color=#000080>运行程序之后,无法正确打印 $data ,只停留在启动tcpdump时两行;</FONT></DIV>
<DIV><FONT face=Verdana color=#000080 size=2></FONT>&nbsp;</DIV><FONT 
face=Verdana color=#000080 size=2>
<HR style="WIDTH: 100px" align=left color=#b5c4df SIZE=1>
</FONT>
<DIV><FONT face=Verdana color=#c0c0c0 size=2>
<DIV>
<DIV><FONT color=#000000>Gary.jsz</FONT></DIV></DIV></FONT></DIV></BODY></HTML>