Snort mailing list archives
Re: Snort rules and flow analysis
From: Alberto Colosi via Snort-users <snort-users () lists snort org>
Date: Fri, 9 Feb 2018 20:33:26 +0000
no fedora or rhel? ... source ? on features I only see stuff around PCAP not logs maybe I haven't seen but is like to handle only pcaps PCAP files Viewer CapAnalysis is a Web pcap file Viewer. It can manage not only one file, but sets of pcap files. The TCP reassembly allows to evaluate the bytes lost for each TCP stream. ________________________________ From: Snort-users <snort-users-bounces () lists snort org> on behalf of James Lay <jlay () slave-tothe-box net> Sent: Friday, February 9, 2018 9:14 PM To: snort-users () lists snort org Subject: Re: [Snort-users] Snort rules and flow analysis Look at either packettotal.com or CapAnalysis: http://www.capanalysis.net/ca/ James On Thu, 2018-02-08 at 21:17 +0000, Alberto Colosi via Snort-users wrote: usually is a SIEM purpose study more sure is said all place ________________________________ From: Snort-users <snort-users-bounces () lists snort org> on behalf of rugg.vale () email it <rugg.vale () email it> Sent: Thursday, February 8, 2018 9:54 PM To: snort-users () lists snort org Subject: [Snort-users] Snort rules and flow analysis Hi I'm an italian student of naples university. I wanted to ask you a question: i've a pcap file with backbone packets. I want compare the result from mawilab anomaly detection, with the output of snort. So i'd like to know if is possible to implemet a flow analysis by snort rule. For example is possible to know how many syn packets an IP send and how many RST the same IP has recive ? thank you for patience. best regards. _______________________________________________ Snort-users mailing list Snort-users () lists snort org<mailto:Snort-users () lists snort org> Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
_______________________________________________ Snort-users mailing list Snort-users () lists snort org Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
Current thread:
- Snort rules and flow analysis rugg . vale (Feb 08)
- Re: Snort rules and flow analysis Alberto Colosi via Snort-users (Feb 08)
- Re: Snort rules and flow analysis James Lay (Feb 09)
- Re: Snort rules and flow analysis Alberto Colosi via Snort-users (Feb 09)
- Message not available
- Re: Snort rules and flow analysis James Lay (Feb 10)
- Re: Snort rules and flow analysis James Lay (Feb 09)
- Re: Snort rules and flow analysis Alberto Colosi via Snort-users (Feb 08)
- Re: Snort rules and flow analysis Paulo Angelo (Feb 13)