Now What?
So you have a Darknet - now what do you do with it? There are a variety of ways to peruse the collected data, and myriad uses for that data.
Perhaps you've heard that there is a bot that exploits Microsoft Windows 2000 open shares. This bot scans on TCP port 445, and you wish to know how much of that traffic is reaching (or sourced within) your network. A quick Argus query to your Darknet will help to answer that question. The query is constructed using tcpdump pattern matching syntax. See the ra man page for more examples.