Snort mailing list archives
Re: configure snort to drop payloads
From: Lyle Sudin <lylesudin () yahoo com>
Date: Tue, 16 Apr 2002 14:05:11 -0700 (PDT)
Hi Erek, -P 64 prints the headers into the ASCII snort directory hiarchy of ip addresses. I need to be able to print the packet headers (and only packet headers) to a single file. Preferably in the binary tcpdump format. Trying -P 64 with -b, seems to be the same as -b. Thanks, Lyle --- Erek Adams <erek () theadamsfamily net> wrote:
On Tue, 2 Apr 2002, Lyle Sudin wrote:Is there an easy way to run snort in packetsniffingmode which will be able to keep up with a 100MB connection, log in tcpdump format, and only logthepacket headers?Yep.The -b switch seems to keep up with the trafficandnot drop packets but includes the payload inadditionto the headers. I need to do all the parsingbeforewriting to disk (both privacy and disk spaceconcerns)so I am looking for either a switch I am missingorcode to edit.No editing needed. Check out the "-P" option. If you just want headers, in the same style as TCPdump, then use "-P 64". Cheers! ----- Erek Adams Nifty-Type-Guy TheAdamsFamily.Net
__________________________________________________ Do You Yahoo!? Yahoo! Tax Center - online filing with TurboTax http://taxes.yahoo.com/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- configure snort to drop payloads Lyle Sudin (Apr 14)
- Re: configure snort to drop payloads Erek Adams (Apr 14)
- Re: configure snort to drop payloads Lyle Sudin (Apr 16)
- Re: configure snort to drop payloads Erek Adams (Apr 16)
- Re: configure snort to drop payloads Lyle Sudin (Apr 17)
- Re: configure snort to drop payloads Erek Adams (Apr 17)
- Re: configure snort to drop payloads Lyle Sudin (Apr 16)
- Re: configure snort to drop payloads Erek Adams (Apr 14)
- Re: configure snort to drop payloads Dr. Richard W. Tibbs (Apr 18)
- Re: configure snort to drop payloads Chris Keladis (Apr 18)
- Re: configure snort to drop payloads Alex Pinheiro Machado Rodrigues (Apr 18)
- Re: Re: configure snort to drop payloads Dr. Richard W. Tibbs (Apr 18)
- Snort sendme email Carlos Augusto Silva (Apr 18)
- Re: Snort sendme email Erek Adams (Apr 18)