Dear Maurizio and Colin,

Thank you for your responses.

It was by mistake that I send an example where BGP messages are not coming from the same peer. All four messages in the example were supposed to have same peer, and announced IP address while different AS-PATH attribute.
In that case I would have three implicit withdrawals, right?

Colin,
 
Are you suggesting that if I look at five-days worth of BGP update messages and trying to count how many implicit withdrawals during that time I have that I need to check first appearance of every announced IP address and check if it is ‘truly’ new announcement or possibly an implicit withdrawal that happened prior to the time frame I am looking at?
Also, I was completely ignoring the state change messages. Are you referring to the messages below? I am not sure what to make out of those.

Best regards,
Ado

TIME: 2001-9-16 00:00:09
TYPE: BGP4MP/BGP4MP_STATE_CHANGE AFI_IP
FROM: 192.65.185.151
OLD STATE: 3  NEW STATE: 2
 
TIME: 2001-9-16 00:00:09
TYPE: BGP4MP/BGP4MP_STATE_CHANGE AFI_IP
FROM: 192.65.185.151
OLD STATE: 2  NEW STATE: 3