Snort mailing list archives

Re: Snort rules and flow analysis


From: James Lay <jlay () slave-tothe-box net>
Date: Sat, 10 Feb 2018 06:41:35 -0700

I use the docker instance..works well:
https://jerrygamblin.com/2016/06/02/capanalysis-container/
James
On Fri, 2018-02-09 at 20:22 +0000, Alberto Colosi wrote:
no fedore or RHEL ?


From: Snort-users <snort-users-bounces () lists snort org> on behalf of
James Lay <jlay () slave-tothe-box net>
Sent: Friday, February 9, 2018 9:14 PM
To: snort-users () lists snort org
Subject: Re: [Snort-users] Snort rules and flow analysis
 
Look at either packettotal.com or CapAnalysis:  http://www.capanalysi
s.net/ca/

James

On Thu, 2018-02-08 at 21:17 +0000, Alberto Colosi via Snort-users
wrote:
usually is a SIEM purpose
study more sure is said all place


From: Snort-users <snort-users-bounces () lists snort org> on behalf
of rugg.vale () email it <rugg.vale () email it>
Sent: Thursday, February 8, 2018 9:54 PM
To: snort-users () lists snort org
Subject: [Snort-users] Snort rules and flow analysis
 
Hi I'm an italian student of naples university. I wanted to ask you
a question: i've a pcap file with backbone packets. I want compare
the result from mawilab anomaly detection, with the output of
snort. So i'd like to know if is possible to implemet a flow
analysis by snort rule. For example is possible to know how many
syn packets an IP send and how many RST the same IP has recive ?
thank you for patience. best regards.
_______________________________________________
Snort-users mailing list
Snort-users () lists snort org
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

Please visit http://blog.snort.org to stay current on all the
latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailin
g-list-etiquette
_______________________________________________
Snort-users mailing list
Snort-users () lists snort org
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Current thread: