Snort mailing list archives
Re: dump packets only p2p rules
From: "Al Lewis (allewi)" <allewi () cisco com>
Date: Mon, 5 Oct 2015 13:33:32 +0000
Hello, Create a rule that matches the traffic you want and then log the traffic. You can also use tagging if you want to capture a certain amount of bytes or for a time period after the initial event. Section on rules --> http://manual.snort.org/node28.html Section on tagging --> http://manual.snort.org/node34.html#SECTION00475000000000000000 Hope this helps. Albert Lewis QA Software Engineer SOURCEfire, Inc. now part of Cisco 9780 Patuxent Woods Drive Columbia, MD 21046 Phone: (office) 443.430.7112 Email: allewi () cisco com From: Jagan mohan Reddy [mailto:jagan.reddy507 () gmail com] Sent: Monday, October 05, 2015 3:05 AM To: snort-devel () lists sourceforge net Subject: [Snort-devel] dump packets only p2p rules Dear Snort, I would like to capture only P2P application network traffic at border router. I have installed SNORT and traffic is mirrored to to one of the server port. How can I capture p2p application traffic ..? -- ---------------------------- Thanks & Regards Jagan mohan reddy http://www.netclique.in/p/jagan-mohan-reddy.html https://github.com/NetClique/idpt_source https://scholar.google.co.in/citations?user=nqpf9sIAAAAJ&hl=en
------------------------------------------------------------------------------
_______________________________________________ Snort-devel mailing list Snort-devel () lists sourceforge net https://lists.sourceforge.net/lists/listinfo/snort-devel Archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel Please visit http://blog.snort.org for the latest news about Snort!
Current thread:
- dump packets only p2p rules Jagan mohan Reddy (Oct 05)
- Re: dump packets only p2p rules Al Lewis (allewi) (Oct 05)
