Snort mailing list archives

Can't read IDS Log


From: Aaron Brown <aeb105 () yahoo com>
Date: Thu, 15 Oct 2015 23:11:15 +0000 (UTC)

Hi, I am new to snort.  Just set it up and ran in intrusion detection mode.  All seems well it reports and when I stop 
it seems to have a bunch of good statistics.   But, when I cat the /var/snort/snort.log I get this stuff below(alot 
more than posted):   When I import it into Wireshark, it says the packet is too big to be imported.    I just want to 
read the logs:


,./!y��+�iT�Vۢ �� ��:j�VۢVۢ N33� ��L
                                                   �I����`:��� �؇����Ƹ�� ��iT�Vۢ T�� ��:j�VۢVۢ TN33� ��L
                                     �I����`:��� �؇8�&Q��h�Ƹ�� ��h<�Vܓ
                                                                             �����DC��VܓVܓ
                    �p������L
�9ZqL                        �I�Eb1�������DCN
        �I��c�Sc5=L
                      �I��2


,./!y��+�iT�Vܓ�� ��:j�VܓVܓN33� ��L
                                                      �I����`:��� �؇����Ƹ�� ��iT�VܓV�� ��:j�VܓVܓVN33� ��L
                                           �I����`:��� �؇8�&Q��h�Ƹ�� ��h<�V�'�>����DC��V�'V�'�>p������L
                                           �I�Eb1�������DCN8���%+L
                                                                        �I��c�Sc5=L
      �I��2


,./!y��+�iT�V����� ��:j�V�'V���N33� ��L
                                                       �I����`:��� �؇����Ƹ�� ��iT�V����� ��:j�V�'V���N33� ��L
                                             �I����`:��� �؇8�&Q��h�Ƹ�� ��h<h�p������L��V��V��
            �I�Eb1�������DCNO��J��L
                                         �I��c�Sc5=L
                                                       �I��2


,./!y��+�iT�V������ ��:j�V��V����N33� ��L
                                                         �I����`:��� �؇����Ƹ�� ��iT�V������ ��:j�V��V����N33� ��L
                                                 �I����`:��� �؇8�&Q��h�Ƹ�� ��h<�V ��r����DC��V �V ��rp������L
                                               �I�Eb1�������DCNw����L
                                                                            �I��c�Sc5=L
          �I��2


,./!y��+�iT�V ��?�� ��:j�V �V ��?N33� ��L
                                                         �I����`:��� �؇����Ƹ�� ��iT�V ����� ��:j�V �V ���N33� ��L
                                                 �I����`:��� �؇8�&Q��h�Ƹ�� ��h<�V�������DC��V�V���p������L
                                           �I�Eb1�������DCNtn/]L
                                                                        �I��c�Sc5=L
      �I��2


,./!y��+�iT�V��p�� ��:j�V�V��pN33� ��L
                                                     �I����`:��� �؇����Ƹ�� ��iT�V�V�� ��:j�V�V�VN33� ��L
                                       �I����`:��� �؇8�&Q��h�Ƹ�� ��h<�V �����DC��V �V �d��������ŬQEV�V@�A����DCB��P
                                                               �3��ŬQ�c�Sc5=��ŬQ�2
9�<
    dhcpcd-5.5.6
                android-59d86c59354bd4b27    !3:;�h<�V �
                                                                 ML����DC��V �V �
          MLd��������ŬQEVD�@5����DCB��P
                                                �3��ŬQ�c�Sc5=��ŬQ�2
9�<
    dhcpcd-5.5.6
                android-59d86c59354bd4b27    !3:;�iT�V     F�����Q�iT�V �6�:��V V �6n33��ŬQц�`8�: �����
                                                                         ���Q�iT�V �l���Q�:j�V V 
�lN33��Q���ŬQц�`:����Qч8!&Q��h������Q�iT�ZZ33��ŬQц�`$�: o ����N33��Q���ŬQц�`:����Qч\��������Q�iT�V 
                                 iT�V /Q����
                                                     :j�V V /QN33���
                                                                            ��ŬQц�`:�����
            ��&Q��h!�4�@��

------------------------------------------------------------------------------
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: