Snort mailing list archives
Re: mysql to pcap?
From: Dirk Geschke <dirk () geschke-online de>
Date: Sat, 30 Aug 2008 21:44:33 +0200
Hi Tim,
I'm viewing snort events through a third-party tool that is fetching the data from the mysql database snort is logging to. I want to be able to select a particular event in the third-party tool and view it in wireshark, so that I can subject the payload to wireshark's protocol parsers.
[...]
But someone must have done this already. Right? :)
you can not do this with the standard database scheme, there are some parameters, especially the headers, missing. I extended the database scheme to allow the storage of the missing parts so that you can rebuild the pcap file. All this is part of FLoP, maybe you should take a look at it: http://www.geschke-online.de/FLoP/ Best regards Dirk -- +----------------------------------------------------------------------+ | Dr. Dirk Geschke / Plankensteinweg 61 / 85435 Erding | | Telefon: 08122-559448 / Mobil: 0176-96906350 / Fax: 08122-9818106 | | dirk () geschke-online de / dirk () lug-erding de / kontakt () lug-erding de | +----------------------------------------------------------------------+ ------------------------------------------------------------------------- This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based applications with Moblin SDK & win great prizes Grand prize is a trip for two to an Open Source event anywhere in the world http://moblin-contest.org/redirect.php?banner_id=100&url=/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- mysql to pcap? Tim Maletic (Aug 29)
- Re: mysql to pcap? Jack Pepper (Aug 29)
- Re: mysql to pcap? Ryan Jordan (Aug 29)
- Re: mysql to pcap? Dirk Geschke (Aug 30)
- Re: mysql to pcap? Jason (Sep 02)
- Re: mysql to pcap? Dirk Geschke (Sep 02)
- Re: mysql to pcap? Jason (Sep 02)
- Re: mysql to pcap? David J. Bianco (Aug 30)
- Re: mysql to pcap? Richard Bejtlich (Aug 31)