PixParser is a free program which can be used to parse Cisco Pix log files to find any search term specified. It will build an HTML file, currently called report.html, with your search results presented. It does a reverse lookup on all IPs, so that you don't have to manually figure out where people have gone via the Internet. Requirements: ■ Cisco Pix Firewall You will need to put the contents of your PixFirewall log files in a directory called /var/log/pixf or wherever you want. The log files should have a suffix of.pix When PixParser runs, it will look for a specific string in the log files and save it's results in a file called report.html. To view your report, open a web browser and point it to the file report.html. This will only return your results for IPs which were on your network at the time you ran PixParser. PixParser can run continuously and will not save any results until you close the program. If you only want to search a very small amount of IP addresses, you can use the checkfor option. This will search for a specific IP address instead of a string and save the results to a file called report.html. See the options page for more information. Sample: # Pix Parser -i -c input.circlog Pix Parser ---> Start Parser Cisco System - TAC Firewall Log -------------------------------- Parsing complete! Output saved to report.html You can edit the format of your report.html using Notepad. Report Format Example: ■ Cisco Pix Firewall Log Example: ■ Cisco TAC Log Format Example: ■ Global Address List File Format Example: ■ Local Address List File Format Example: ■ Domain Address List File Format Example: 1 - How to get the Cisco Pix Log to parse: For the output format of Cisco Pix Firewall log to work you must run Pix Parser via Cisco TAC on a current supported version of Cisco Pix. You must also have a copy of the Cisco TAC log which you want to run Pix Parser on. Pix Parser will be able to read the log file directly and not need to run via Cisco TAC. 2 - How to run Pix Parser: Running Pix Parser will cause the output log file from the Cisco Pix firewall to be displayed on your computer. Pix Parser is a stand-alone application and does not require Cisco TAC. 3 - How to convert Log Files to CSV format: If you have a log file of any other format which you wish to parse via Pix Parser, you will need to save the file as a CSV file. You can then import the CSV file into Pix Parser using the file menu. 4 - How to Export Reports to a file: Pix Parser allows you to export reports to a file (report.html). 5 - How to Export Reports to a CSV file: If you wish to save reports in CSV format, you can do this by exporting the report to a file. 6 - How to set the IP Range in the report: To include or exclude IP addresses in a Pix Parser report, there is an input box located on the top Copyright (c) 1999-2002 Bertil Meyerhoffer ( This file is part of the PicoGL(TM) Project Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. Version 2.0.0: ■ Added Local IP filtering ■ Pcap support ■ ISO-8859-1 encoding support ■ More pcap format ■ More samples ■ More platform ■ More output format ■ Self-contained binary What's new in Version 1.3.0: ■ Local IP filtering ■ Platform detection What's new in Version 1.2.1: ■ Added user-friendly encoding support What's new in Version 1.1.1: ■ API support What's new in Version 1.0.1: ■ First public release Report bugs at: Find a bug? Please report it at: News: Installation PixParser can be obtained by: ■ cvs -d co vx ■ cd vx/ ■./configure ■ make ■ make install Note that if you get the following error: configure: error: 'XSLTPROC' file does not exist! I suggest you install cxml-xsl-1.1.8.tar.gz and XSLTPROC-1.1.3.tar.gz Contribute PixParser development and maintenance is a free program, but any feedback is always welcome. Thank you for contributing to the development of PixParser! Note: ■ Make sure you do a cvs update ■ Make sure your PixParser is up to date Note: ■ Only use the latest version of the software. ■ Remove previous versions. ■ PixParser v1.0.1 and earlier are not supported. ■ PixParser v1.0.2 System Requirements: OS: Mac OS X 10.5.8 or later Mac OS X 10.5.8 or later CPU: 2.66GHz G5 2.66GHz G5 RAM: 4GB 4GB HDD: 35GB 35GB CD-RW (CD-R or CD-RW DL) 3.5" CD-RW or DVD-RW Windows: XP XP Processor: 2.66GHz Pentium 4 2.66GHz Pentium 4 RAM: 4GB

