ARP = Address Resolution Protocol

In order for a TCP/IP network to work, it also needs to know what 
hardware address packets should be sent to (i.e. the hardware address of 
the NIC in your computer..)

So this is one box broadcasting a request for the hardware address 
("who-has [the hardware address for]") and saying that the 
answer should be sent to it ("tell")

The response would be "arp reply is at 0:a5:32:ae:40:21" or 

Are you actually seeing ""?

It should be an actual IP address, methinks...

Sounds like you're running snort with the -e command line switch 
("Display/log the link layer packet headers")

You may want to turn that off; it get kinda boring after you've seen a 
few thousand of the same thing.

Jason Withrow wrote:

> Sorry about the flood I am creating here, one last question.
> What the heck is this ARP file that SNORT Keeps creating, it is filled
> with stuff like this:
>         09/16-03:57:48.234413 ARP who-has tell
>         09/16-03:57:48.400994 ARP who-has tell
> What is this stuff?
> Thanks,
> - J

