Re: dump packets only p2p rules
"Al Lewis (allewi)" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.devel |
|---|---|
| Message-ID | <[email protected]> |
Hello, Create a rule that matches the traffic you want and then log the traffic. You can also use tagging if you want to capture a certain amount of bytes or for a time period after the initial event. Section on rules --> http://manual.snort.org/node28.html Section on tagging --> http://manual.snort.org/node34.html#SECTION00475000000000000000 Hope this helps. Albert Lewis QA Software Engineer SOURCEfire, Inc. now part of Cisco 9780 Patuxent Woods Drive Columbia, MD 21046 Phone: (office) 443.430.7112 Email: [email protected] From: Jagan mohan Reddy [mailto:[email protected]] Sent: Monday, October 05, 2015 3:05 AM To: [email protected] Subject: [Snort-devel] dump packets only p2p rules Dear Snort, I would like to capture only P2P application network traffic at border router. I have installed SNORT and traffic is mirrored to to one of the server port. How can I capture p2p application traffic ..? -- ---------------------------- Thanks & Regards Jagan mohan reddy http://www.netclique.in/p/jagan-mohan-reddy.html https://github.com/NetClique/idpt_source https://scholar.google.co.in/citations?user=nqpf9sIAAAAJ&hl=en ------------------------------------------------------------------------------ _______________________________________________ Snort-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/snort-devel Archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel Please visit http://blog.snort.org for the latest news about Snort!