Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 7 Problems Up: 6 Getting Fancy Previous: 6.15 How do I

6.16 How can I examine logged packets in more detail?

If you are using unified logging, you can use Barnyard (see FAQ [*]) or the unified log to pcap converter written by Dragos:

http://dragos.com/logtopcap.c

You can then get additional decoding of the packet contents by analyzing these pcap files with either:

  • Tcpdump - http://www.tcpdump.org
  • Ethereal - http://www.ethereal.com



Nigel Houghton 2006-10-02