[Snort-users] Snort rules and flow analysis

James Lay jlay at slave-tothe-box.net
Fri Feb 9 15:14:21 EST 2018


Look at either packettotal.com or CapAnalysis:  http://www.capanalysis.
net/ca/
James
On Thu, 2018-02-08 at 21:17 +0000, Alberto Colosi via Snort-users
wrote:
> usually is a SIEM purpose
> study more sure is said all place
> 
> 
> From: Snort-users <snort-users-bounces at lists.snort.org> on behalf of 
> rugg.vale at email.it <rugg.vale at email.it>
> Sent: Thursday, February 8, 2018 9:54 PM
> To: snort-users at lists.snort.org
> Subject: [Snort-users] Snort rules and flow analysis
>  
> Hi I'm an italian student of naples university. I wanted to ask you a
> question: i've a pcap file with backbone packets. I want compare the
> result from mawilab anomaly detection, with the output of snort. So
> i'd like to know if is possible to implemet a flow analysis by snort
> rule. For example is possible to know how many syn packets an IP send
> and how many RST the same IP has recive ? thank you for patience.
> best regards.
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.snort.org
> Go to this URL to change user options or unsubscribe:
> https://lists.snort.org/mailman/listinfo/snort-users
> 
> Please visit http://blog.snort.org to stay current on all the latest
> Snort news!
> 
> Please follow these rules: https://snort.org/faq/what-is-the-mailing-
> list-etiquette
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20180209/b6e0b2de/attachment.html>


More information about the Snort-users mailing list