Snort mailing list archives

Re: whether wireshark can be integrated with snort??


From: Nigel Houghton <nhoughton () sourcefire com>
Date: Mon, 25 May 2009 10:59:37 -0400

On Mon, May 25, 2009 at 7:20 AM, Sadanand Ghagare <sadanandgh () gmail com> wrote:
Hi Nigel,

Wireshark box has been used by sys-admin and that directly connected to
mirrored port. They use that box to monitor traffic.
I am totally unaware about whether they dump the data or they use it in real
time.
But to make snort working I can ask them to do it.

I think you really need to find out what they are doing with wireshark
first. I also think you might find that snort needs to replace that
wireshark instance if they are really monitoring network traffic.

-- 
Nigel Houghton
Head Mentalist
SF VRT
http://vrt-sourcefire.blogspot.com && http://www.snort.org/vrt/

------------------------------------------------------------------------------
Register Now for Creativity and Technology (CaT), June 3rd, NYC. CaT
is a gathering of tech-side developers & brand creativity professionals. Meet
the minds behind Google Creative Lab, Visual Complexity, Processing, & 
iPhoneDevCamp asthey present alongside digital heavyweights like Barbarian
Group, R/GA, & Big Spaceship. http://www.creativitycat.com 
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: