Snort mailing list archives

Re: file format


From: "Joel Esler (jesler)" <jesler () cisco com>
Date: Mon, 12 Sep 2016 15:10:44 +0000

You need to have Snort read the pcap files.

(the .tcpdump files)

--
Joel Esler
Manager
Talos Group
http://www.talosintelligence.com


On Sep 12, 2016, at 5:19 AM, Ikenna Chiadikaobi <reniykec () yahoo com<mailto:reniykec () yahoo com>> wrote:

hi everyone, i have a dataset in .7z format and i have unzip it, but i want to run it in this snort mode  ( sudo snort 
-r  dataset -c snort.conf), pls, which format can the dataset be to enable me run this. Darpa is in .tcpdump extension 
and once replace the darpa with the dataset in  sudo snort -r  dataset -c snort.conf , it runs. But i want to use 
Kaggle dataset. How can i make this work.

Thanks,
Ikenna
------------------------------------------------------------------------------
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net<mailto:Snort-users () lists sourceforge net>
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

------------------------------------------------------------------------------
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: