Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-users] Snort dont understand pf (openbsd) format |
|---|---|
| Date: | Mon, 29 Nov 2004 18:27:24 -0500 |
leitao@anthem:~/snort/snort-2.3.0RC1/src$ ./snort -c snort.conf -l /tmp -r ~/tmp/pflog.2
<snip>
What is wrong with that? Does snort understand the pf log format?
No, snort doesn't understand any textual log formats at all, including pf.
From the snort manpage:
-r tcpdump-file
Read the tcpdump-formatted file tcpdump-file. This
will cause Snort to read and process the file fed
to it. This is useful if, for instance, you've got
a bunch of SHADOW files that you want to process
for content, or even if you've got a bunch of
reassembled packet fragments which have been writ-
ten into a tcpdump formatted file.| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-users] Snort dont understand pf (openbsd) format, Breno Leitão |
|---|---|
| Next by Date: | Re: [Snort-users] Snort dont understand pf (openbsd) format, Matt Kettler |
| Previous by Thread: | [Snort-users] Snort dont understand pf (openbsd) format, Breno Leitão |
| Next by Thread: | Re: [Snort-users] Snort dont understand pf (openbsd) format, Matt Kettler |
| Indexes: | [Date] [Thread] [Top] [All Lists] |