[Snort-users] pcap format

Joel Esler jesler at ...1935...
Fri Dec 11 08:43:11 EST 2009


On 12/11/09 6:01 AM, Pradeep Lamabam wrote:
> hi
> i am working with snort ,barnyard2 which works fine in the sense, the
> configuration logs properly in mysql database which can be used with BASE.
> what i was looking for is how to log alerts with payload (ie, the whole
> packet) so that i can use the data with some protocol analyser like
> wireshark.
> i would appreciate if the configuration/settings can be done in
> barnyard2.conf file.
>


Use the log_tcpdump format in barnyard2.

J




More information about the Snort-users mailing list