Snort mailing list archives

Re: reading log files


From: Russ Combs <rcombs () sourcefire com>
Date: Thu, 5 Jul 2012 14:37:57 -0400

On Thu, Jul 5, 2012 at 11:25 AM, Lay, James <james.lay () wincofoods com>wrote:

*From:* Pratik Narang [mailto:pratik.cse.bits () gmail com]
*Sent:* Thursday, July 05, 2012 12:32 AM
*To:* snort-users () lists sourceforge net
*Subject:* [Snort-users] reading log files****

** **

Hi all,

Some one please, please help me out- HOW do i read the log files generated
with Snort??? - snort.log.<timestamp>

And WHAT about those generate using Barnyard2 - snort.u2.<timestamp> ???**
**

** **

Pratik,****

** **

The snort.log.timestamp files are text…anything that reads text files will
work.  As for the u2 files, those are unified binary files…read with
u2spewfoo that should have come with Snort.  Help that helps.****

** **

James


You can also use u2boat, another utility that comes with Snort, to convert
the u2 packets to pcap to view with Wireshark.

****


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and
threat landscape has changed and how IT managers can respond. Discussions
will include endpoint security, mobile security and the latest in malware
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest
Snort news!

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: