[Snort-users] I've just noticed that my linux snort is no longer using PCAP_FRAMES ???

Phil Wood cpw at ...440...
Wed May 12 10:42:44 EDT 2010


PCAP_FRAMES is only understood by the libpcap at:

  http://public.lanl.gov/cpw/libpcap-0.9.8.20081128.tar.gz

As far as I know the latest libpcap at tcpdump.org is libpcap-1.1.1.  It
has source code to use a ring buffer but I have not had time to try it
out.  For all I know, it could be the default.  But, I don't think they
went so far as to use my PCAP_FRAMES gimmick.

Later,

-- 
C. Philip Wood, Int. D.
Senior Member of the Internet
Los Alamos National Laboratory
Key fingerprint: 2BB7 A990 44F5 EF4B 4E35  8635 1205 97D3 F6D8 7F39
E-mail: cpw at ...440..., cornett at ...1649...
Phone: 505 667-2598
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 197 bytes
Desc: This is a digitally signed message part
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20100512/3af3fb9f/attachment.sig>


More information about the Snort-users mailing list