Snort mailing list archives

Re: snort + mysql


From: "Paul Melson" <pmelson () gmail com>
Date: Thu, 24 Apr 2008 20:59:37 -0400

On Wed, Apr 23, 2008 at 3:52 PM, Joel Esler <joel.esler () sourcefire com> wrote:
Sguil shows which packets are dropped?  And, on that end..  Arcsight does?

Since drops show up wherever you send 'full' logs to, I would think
anything that can handle full logs would display drop messages.  I
have done this successfully with ArcSight, but I admit that I was just
guessing about Sguil.  But mostly, I was hassling you. :-)

PaulM

-------------------------------------------------------------------------
This SF.net email is sponsored by the 2008 JavaOne(SM) Conference 
Don't miss this year's exciting event. There's still time to save $100. 
Use priority code J8TL2D2. 
http://ad.doubleclick.net/clk;198757673;13503038;p?http://java.sun.com/javaone
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: