Snort mailing list archives
Re: snort_stat.pl
From: stephane nasdrovisky <stephane.nasdrovisky () paradigmo com>
Date: Wed, 20 Oct 2004 17:07:38 +0200
Rob Ward wrote:
Perl 5.6 snort_stat.pl 1.15.2.6When I run the 'alert' file produced by Snort through snort_stat.pl it doesn't produce any data yet the file is full of alerts. I've seen others with similar problems in the archives. Has anyone resolved this?The strange thing is I also use grep to produce a file of DOS and DDOS alerts from the 'alert' file and when I run this through snort_stat.pl this produces output?
Is your alert file larger than 2gb ? It may be related to some restriction on the file size (2 or 4 gb, I can't remember). If grep is producing a file smaller than 2gb, game is over. You may upgrade your perl to an uptodate one 5.8? It seems perl 5.6.1 is largefile (>2 or 4 gb) ready. Google for "perl largefile" for more info.
------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- snort_stat.pl Rob Ward (Oct 20)
- Re: snort_stat.pl stephane nasdrovisky (Oct 20)
- Re: snort_stat.pl Rob Ward (Oct 20)
- Re: snort_stat.pl jeremy . chartier (Oct 20)
- Re: snort_stat.pl stephane nasdrovisky (Oct 20)