Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 2 Getting Started Up: 1 Background Previous: 1.10 Can Snort be

1.11 Does Snort log the full packets when it generates alerts?

Yes, the packets should be in the directory that has the same IP address as the source host of the packet which generated the alert. If you are using binary logging, there will be a packet capture file (.pcap) in the logging directory instead.