[Snort-users] NIDS on large (>500MB) pcap dumps

Steve Marotta smarotta at ...16014...
Thu Dec 13 16:14:43 EST 2012


Is there a way to run Snort in NIDS mode on large (>500MB) pcap dumps? When I try to run snort -dev -l (mylog) -r (myfile) -c /etc/snort.conf, I get, "Value too large for defined data type" and "ERROR: Error getting pcaps".

Is this because the file I'm reading is too large? If so, is there a workaround?

THIS MESSAGE IS INTENDED FOR THE USE OF THE PERSON TO WHOM IT IS ADDRESSED. IT MAY CONTAIN INFORMATION THAT IS PRIVILEGED, CONFIDENTIAL AND EXEMPT FROM DISCLOSURE UNDER APPLICABLE LAW. If you are not the intended recipient, your use of this message for any purpose is strictly prohibited. If you have received this communication in error, please delete the message and notify the sender so that we may correct our records.

More information about the Snort-users mailing list