snort-users May 2009 archive
Main Archive Page > Month Archives  > snort-users archives
snort-users: Re: [Snort-users] tcpdump file analysis

Re: [Snort-users] tcpdump file analysis

From: Joel Esler <jesler_at_nospam>
Date: Sun May 03 2009 - 08:32:45 GMT
To: Oguz Yarimtepe <>

Oguz Yarimtepe said:
> Hi,
> I want to analyze a prerecorded tcpdump file via snort. I checked that
> snort can read pcap files with -r parameter. I want to know whether i
> can send the generated results to mysql database and see the results
> from base interface.

Yes, If you run Snort as you would any other time in IPS mode "-c", and simply use the output plugins you have defined in your snort.conf, when you run Snort with the -r option, it will log the alerts generated from your pcap normally.


Register Now & Save for Velocity, the Web Performance & Operations Conference from O'Reilly Media. Velocity features a full day of expert-led, hands-on workshops and two days of sessions from industry leaders in dedicated Performance & Operations tracks. Use code vel09scf and Save an extra 15% before 5/3.

Snort-users mailing list
Go to this URL to change user options or unsubscribe: Snort-users list archive: