Snort mailing list archives

Re: Grouping connections


From: Nerijus Krukauskas <nkrukauskas () gmail com>
Date: Thu, 23 Apr 2009 08:04:26 +0300

On 2009-04-22, Ulisses Araújo Costa <ulissesaraujocosta () gmail com> wrote:
Hi Leon,

what I want is to record that the request X have the response Y. What I
explained, is that probably the request X is just a packet, but the response
Y is 4 packets. The only thing I want to know is that the flow X <> Y
happened.

Flowbits? http://snort.org/docs/snort_htmanuals/htmanual_284/node322.html.

-- 
http://nk99.org/

------------------------------------------------------------------------------
Stay on top of everything new and different, both inside and 
around Java (TM) technology - register by April 22, and save
$200 on the JavaOne (SM) conference, June 2-5, 2009, San Francisco.
300 plus technical and hands-on sessions. Register today. 
Use priority code J9JMT32. http://p.sf.net/sfu/p
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: