[Snort-users] Snort rules and flow analysis

Alberto Colosi alcol at hotmail.com
Fri Feb 9 15:33:26 EST 2018


no fedora or rhel? ... source ?


on features I only see stuff around PCAP not logs

maybe I haven't seen but is like to handle only pcaps


PCAP files Viewer

CapAnalysis is a Web pcap file Viewer. It can manage not only one file, but sets of pcap files.
The TCP reassembly allows to evaluate the bytes lost for each TCP stream.


________________________________
From: Snort-users <snort-users-bounces at lists.snort.org> on behalf of James Lay <jlay at slave-tothe-box.net>
Sent: Friday, February 9, 2018 9:14 PM
To: snort-users at lists.snort.org
Subject: Re: [Snort-users] Snort rules and flow analysis

Look at either packettotal.com or CapAnalysis:  http://www.capanalysis.net/ca/

James

On Thu, 2018-02-08 at 21:17 +0000, Alberto Colosi via Snort-users wrote:

usually is a SIEM purpose

study more sure is said all place


________________________________
From: Snort-users <snort-users-bounces at lists.snort.org> on behalf of rugg.vale at email.it <rugg.vale at email.it>
Sent: Thursday, February 8, 2018 9:54 PM
To: snort-users at lists.snort.org
Subject: [Snort-users] Snort rules and flow analysis

Hi I'm an italian student of naples university. I wanted to ask you a question: i've a pcap file with backbone packets. I want compare the result from mawilab anomaly detection, with the output of snort. So i'd like to know if is possible to implemet a flow analysis by snort rule. For example is possible to know how many syn packets an IP send and how many RST the same IP has recive ? thank you for patience. best regards.

_______________________________________________
Snort-users mailing list
Snort-users at lists.snort.org<mailto:Snort-users at lists.snort.org>
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20180209/bfb7e39d/attachment-0001.html>


More information about the Snort-users mailing list