Snort mailing list archives

Re: capturing a suspisous traffic stream


From: Chris Green <cmg () uab edu>
Date: Mon, 22 Oct 2001 22:28:39 -0500

"Stan Scalsky" <sscalsk () mail ameritel net> writes:

that is cool and just what I was looking to do also - how about in addition
to # of seconds maybe # of packets? say "tag: session, 50, packets;" to grab
up to the next 50 packets. or can i already do this elsewhere?

yes. With that same syntax.  docs seem to be messed up on snort.org at
the moment.

We'll get that fixed.
-- 
Chris Green <cmg () uab edu>
 "Not everyone holds these truths to be self-evident, so we've worked
                  up a proof of them as Appendix A." --  Paul Prescod

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: