[Collisions] Datasets to use for older years

Roy Hooper roy at demandmedia.com
Thu Sep 26 19:16:14 UTC 2013


Thanks for the clarification on how the CLEAN data sets differ from RAW, Duane!

The CLEAN directories sound like they're a much better data set to work from for any analysis that is not comparing directly against the Intersite report.


-Roy

On 2013-09-26, at 3:02 PM, "Wessels, Duane" <dwessels at verisign.com<mailto:dwessels at verisign.com>> wrote:

You should be able to find CLEAN data for every year, if you prefer that.
FYI the clean data differs from the raw data in the following ways:

  - files begin and end on consistent time boundaries.
  - pcap files have the same datalink type.
  - Any non-root traffic is removed.

If you prefer to work with the RAW data make sure you pay attention to the
server's IP address during the analysis.  In some cases non-root-trafic
has been known to "leak" into the DITL data.  Also there were times where
J-root data was uploaded as A-root, and perhaps vice-versa.

DW


________________________________
Please NOTE: This electronic message, including any attachments, may include privileged, confidential and/or inside information owned by Demand Media, Inc. Any distribution or use of this communication by anyone other than the intended recipient(s) is strictly prohibited and may be unlawful. If you are not the intended recipient, please notify the sender by replying to this message and then delete it from your system. Thank you.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.dns-oarc.net/pipermail/collisions/attachments/20130926/a2b17993/attachment.htm>


More information about the Collisions mailing list