Snort mailing list archives

Re: dump packets only p2p rules


From: "Al Lewis (allewi)" <allewi () cisco com>
Date: Mon, 5 Oct 2015 13:33:32 +0000

Hello,

Create a rule that matches the traffic you want and then log the traffic.

You can also use tagging if you want to capture a certain amount of bytes or for a time period after the initial event.


Section on rules --> http://manual.snort.org/node28.html

Section on tagging --> http://manual.snort.org/node34.html#SECTION00475000000000000000


Hope this helps.


Albert Lewis
QA Software Engineer
SOURCEfire, Inc. now part of Cisco
9780 Patuxent Woods Drive
Columbia, MD 21046
Phone: (office) 443.430.7112
Email: allewi () cisco com

From: Jagan mohan Reddy [mailto:jagan.reddy507 () gmail com]
Sent: Monday, October 05, 2015 3:05 AM
To: snort-devel () lists sourceforge net
Subject: [Snort-devel] dump packets only p2p rules

Dear Snort,

I would like to capture only P2P application network traffic at border router. I have installed SNORT and traffic is 
mirrored to to one of the server port. How can I capture p2p application traffic ..?

--
----------------------------
Thanks & Regards
Jagan mohan reddy
http://www.netclique.in/p/jagan-mohan-reddy.html
https://github.com/NetClique/idpt_source
https://scholar.google.co.in/citations?user=nqpf9sIAAAAJ&hl=en

------------------------------------------------------------------------------
_______________________________________________
Snort-devel mailing list
Snort-devel () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-devel
Archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel

Please visit http://blog.snort.org for the latest news about Snort!

Current thread: