[Snort-users] Snort rules and flow analysis

James Lay jlay at slave-tothe-box.net
Sat Feb 10 08:41:35 EST 2018


I use the docker instance..works well:
https://jerrygamblin.com/2016/06/02/capanalysis-container/
James
On Fri, 2018-02-09 at 20:22 +0000, Alberto Colosi wrote:
> no fedore or RHEL ?
> 
> 
> From: Snort-users <snort-users-bounces at lists.snort.org> on behalf of
> James Lay <jlay at slave-tothe-box.net>
> Sent: Friday, February 9, 2018 9:14 PM
> To: snort-users at lists.snort.org
> Subject: Re: [Snort-users] Snort rules and flow analysis
>  
> Look at either packettotal.com or CapAnalysis:  http://www.capanalysi
> s.net/ca/
> 
> James
> 
> On Thu, 2018-02-08 at 21:17 +0000, Alberto Colosi via Snort-users
> wrote:
> > usually is a SIEM purpose
> > study more sure is said all place
> > 
> > 
> > From: Snort-users <snort-users-bounces at lists.snort.org> on behalf
> > of rugg.vale at email.it <rugg.vale at email.it>
> > Sent: Thursday, February 8, 2018 9:54 PM
> > To: snort-users at lists.snort.org
> > Subject: [Snort-users] Snort rules and flow analysis
> >  
> > Hi I'm an italian student of naples university. I wanted to ask you
> > a question: i've a pcap file with backbone packets. I want compare
> > the result from mawilab anomaly detection, with the output of
> > snort. So i'd like to know if is possible to implemet a flow
> > analysis by snort rule. For example is possible to know how many
> > syn packets an IP send and how many RST the same IP has recive ?
> > thank you for patience. best regards.
> > _______________________________________________
> > Snort-users mailing list
> > Snort-users at lists.snort.org
> > Go to this URL to change user options or unsubscribe:
> > https://lists.snort.org/mailman/listinfo/snort-users
> > 
> > Please visit http://blog.snort.org to stay current on all the
> > latest Snort news!
> > 
> > Please follow these rules: https://snort.org/faq/what-is-the-mailin
> > g-list-etiquette
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20180210/6116ad95/attachment.html>


More information about the Snort-users mailing list