Snort mailing list archives

Re: HTTP reassembly problem


From: beenph <beenph () gmail com>
Date: Wed, 10 Oct 2012 13:55:37 -0400

On Wed, Oct 10, 2012 at 1:51 PM, João Lima
<joao.pedro.paulino.lima () gmail com> wrote:
No. I'm using output unified2

In most cases I'm able to get the packet from the event.

Only when reassembled packets are involved, the unified2Packet is missing.

João Lima
And are you using snort >= 2.9.3.x?


-elz

------------------------------------------------------------------------------
Don't let slow site performance ruin your business. Deploy New Relic APM
Deploy New Relic app performance management and know exactly
what is happening inside your Ruby, Python, PHP, Java, and .NET app
Try New Relic at no cost today and get our sweet Data Nerd shirt too!
http://p.sf.net/sfu/newrelic-dev2dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: