Snort mailing list archives
Re: mysql to pcap?
From: Jason <security () brvenik com>
Date: Tue, 02 Sep 2008 10:28:59 -0400
Dirk Geschke wrote:
Hi Tim,I'm viewing snort events through a third-party tool that is fetching the data from the mysql database snort is logging to. I want to be able to select a particular event in the third-party tool and view it in wireshark, so that I can subject the payload to wireshark's protocol parsers.[...]But someone must have done this already. Right? :)you can not do this with the standard database scheme, there are some parameters, especially the headers, missing.
What is missing? You should be able to take the binary data and wrap a pcap header on it and all should be well. Details please.
I extended the database scheme to allow the storage of the missing parts so that you can rebuild the pcap file. All this is part of FLoP, maybe you should take a look at it: http://www.geschke-online.de/FLoP/ Best regards Dirk
------------------------------------------------------------------------- This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based applications with Moblin SDK & win great prizes Grand prize is a trip for two to an Open Source event anywhere in the world http://moblin-contest.org/redirect.php?banner_id=100&url=/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- mysql to pcap? Tim Maletic (Aug 29)
- Re: mysql to pcap? Jack Pepper (Aug 29)
- Re: mysql to pcap? Ryan Jordan (Aug 29)
- Re: mysql to pcap? Dirk Geschke (Aug 30)
- Re: mysql to pcap? Jason (Sep 02)
- Re: mysql to pcap? Dirk Geschke (Sep 02)
- Re: mysql to pcap? Jason (Sep 02)
- Re: mysql to pcap? David J. Bianco (Aug 30)
- Re: mysql to pcap? Richard Bejtlich (Aug 31)