Snort mailing list archives

Re: Snort rules and flow analysis


From: Alberto Colosi via Snort-users <snort-users () lists snort org>
Date: Fri, 9 Feb 2018 20:33:26 +0000

no fedora or rhel? ... source ?


on features I only see stuff around PCAP not logs

maybe I haven't seen but is like to handle only pcaps


PCAP files Viewer

CapAnalysis is a Web pcap file Viewer. It can manage not only one file, but sets of pcap files.
The TCP reassembly allows to evaluate the bytes lost for each TCP stream.


________________________________
From: Snort-users <snort-users-bounces () lists snort org> on behalf of James Lay <jlay () slave-tothe-box net>
Sent: Friday, February 9, 2018 9:14 PM
To: snort-users () lists snort org
Subject: Re: [Snort-users] Snort rules and flow analysis

Look at either packettotal.com or CapAnalysis:  http://www.capanalysis.net/ca/

James

On Thu, 2018-02-08 at 21:17 +0000, Alberto Colosi via Snort-users wrote:

usually is a SIEM purpose

study more sure is said all place


________________________________
From: Snort-users <snort-users-bounces () lists snort org> on behalf of rugg.vale () email it <rugg.vale () email it>
Sent: Thursday, February 8, 2018 9:54 PM
To: snort-users () lists snort org
Subject: [Snort-users] Snort rules and flow analysis

Hi I'm an italian student of naples university. I wanted to ask you a question: i've a pcap file with backbone packets. 
I want compare the result from mawilab anomaly detection, with the output of snort. So i'd like to know if is possible 
to implemet a flow analysis by snort rule. For example is possible to know how many syn packets an IP send and how many 
RST the same IP has recive ? thank you for patience. best regards.

_______________________________________________
Snort-users mailing list
Snort-users () lists snort org<mailto:Snort-users () lists snort org>
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

_______________________________________________
Snort-users mailing list
Snort-users () lists snort org
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Current thread: