IDS mailing list archives
WINDUMP SYNTAX ASSISTANCE.....
From: "Jason Beauford" <Jbeauford () mill-max com>
Date: Tue, 28 Jan 2003 12:27:26 -0500
Forum, I am looking for the Windump syntax to record only the packets that involve a particular host and those hosts outside of our internal network. I've tried the "host hostname and not src net localnet, but I am still missing half of the traffic as it only gives me ingress traffic. I still need to record egress traffic. So I try host hostname and not dst net localnet. This gives me only egress and not ingress. If I try without same syntax without the src or dst, I get no traffic. Can anyone point me in the right direction with this? Thanks in advance. Regards, Jason M. Beauford.
Current thread:
- WINDUMP SYNTAX ASSISTANCE..... Jason Beauford (Jan 28)