Snort mailing list archives

-d packet capture


From: Greg Sarsons <gsarsons () home com>
Date: Fri, 21 Sep 2001 18:50:42 -0400

Is there a way to not grab the whole packet with snort?  For example in
tcpdump I can set the size.  If I don't want to grab the whole packet am
I better off grabbing with tcpdump and then using snort after?

When dumping to binary file and is either snort or tcpdump(grabbing the
whole packet) more efficient?

Greg

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: