Snort mailing list archives
Re: pcap format
From: Joel Esler <jesler () sourcefire com>
Date: Fri, 11 Dec 2009 08:43:11 -0500
On 12/11/09 6:01 AM, Pradeep Lamabam wrote:
hi i am working with snort ,barnyard2 which works fine in the sense, the configuration logs properly in mysql database which can be used with BASE. what i was looking for is how to log alerts with payload (ie, the whole packet) so that i can use the data with some protocol analyser like wireshark. i would appreciate if the configuration/settings can be done in barnyard2.conf file.
Use the log_tcpdump format in barnyard2. J ------------------------------------------------------------------------------ Return on Information: Google Enterprise Search pays you back Get the facts. http://p.sf.net/sfu/google-dev2dev _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- pcap format Pradeep Lamabam (Dec 11)
- Re: pcap format Joel Esler (Dec 11)