Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 3 Configuring Snort Up: 2 Getting Started Previous: 2.14 What are CIDR

2.15 What is the use of the ``-r'' switch to read tcpdump files?

Used in conjunction with a Snort rules file, the tcpdump data can be analyzed for hostile content, port scans, or anything else Snort can be used to detect. Snort can also display the packets in a decoded format, which many people find is easier to read than native tcpdump output.