Re: dump packets only p2p rules

"Al Lewis (allewi)" <[email protected]>
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <[email protected]>
Hello,

Create a rule that matches the traffic you want and then log the traffic.

You can also use tagging if you want to capture a certain amount of bytes or for a time period after the initial event.


Section on rules --> http://manual.snort.org/node28.html

Section on tagging --> http://manual.snort.org/node34.html#SECTION00475000000000000000


Hope this helps.


Albert Lewis
QA Software Engineer
SOURCEfire, Inc. now part of Cisco
9780 Patuxent Woods Drive
Columbia, MD 21046
Phone: (office) 443.430.7112
Email: [email protected]

From: Jagan mohan Reddy [mailto:[email protected]]
Sent: Monday, October 05, 2015 3:05 AM
To: [email protected]
Subject: [Snort-devel] dump packets only p2p rules

Dear Snort,

I would like to capture only P2P application network traffic at border router. I have installed SNORT and traffic is mirrored to to one of the server port. How can I capture p2p application traffic ..?

--
----------------------------
Thanks & Regards
Jagan mohan reddy
http://www.netclique.in/p/jagan-mohan-reddy.html
https://github.com/NetClique/idpt_source
https://scholar.google.co.in/citations?user=nqpf9sIAAAAJ&hl=en

------------------------------------------------------------------------------

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/snort-devel
Archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel

Please visit http://blog.snort.org for the latest news about Snort!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.