Snort mailing list archives

newbie snort question


From: "/dev/null" <dev.null () beginthread com>
Date: Tue, 10 Sep 2002 20:34:17 -0500

I'm reading through the manual right now, but haven't seen anything along
these lines just yet.

If I save packets from snort or other util like tcpdump, can I re-run snort
and pass in that packet file and get snort to run as if it were actual
network traffic?

Thanks!

/dev/null 
Available for Consulting.

email: dev.null () beginthread com
web: www.BeginThread.com/dev.null
* Would you like to join BeginThread.com?  Drop me a line, it's FREE!

Attachment: Status
Description:

Attachment: ArticleCountThousand
Description:

Attachment: ArticleCountHundred
Description:

Attachment: ArticleCountTen
Description:

Attachment: ArticleCountOne
Description:


Current thread: