[Snort-users] whether wireshark can be integrated with snort??

Stephen Mullins steve.mullins.work at ...11827...
Sat May 23 16:04:45 EDT 2009


I would suggest you use Sguil with Snort and you can launch wireshark
from Sguil if needed.

Or you could use an inline network TAP on the cable running from the
SPAN port to the Wireshark box to "split" the signal so it goes to
both the Snort sensor and the Wireshark box.

Steve Mullins

On Tue, May 19, 2009 at 12:01 PM, Sadanand Ghagare <sadanandgh at ...11827...> wrote:
> Hi
>
> We are in process to implement snort as network sensor in our network. But
> problem here is, we already have wireshark machine connected to monitoring
> port of switch and we don't want to disturb existing setup.
> So whether it is possible to integrate snort with wireshark so that snort
> can analyze the packets captured by wireshark as per snort rule base.
> If yes, how to configure it.
> I hope I am up to the point for my requirements.
>
> --
>
>
> Thanks & Regards
>
> Sadanand G.
>
> ------------------------------------------------------------------------------
> Crystal Reports - New Free Runtime and 30 Day Trial
> Check out the new simplified licensing option that enables
> unlimited royalty-free distribution of the report engine
> for externally facing server and web deployment.
> http://p.sf.net/sfu/businessobjects
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>




More information about the Snort-users mailing list