snort-users May 2009 archive
Main Archive Page > Month Archives  > snort-users archives
snort-users: Re: [Snort-users] whether wireshark can be integrat

Re: [Snort-users] whether wireshark can be integrated with snort??

From: Sadanand Ghagare <sadanandgh_at_nospam>
Date: Mon May 25 2009 - 11:20:55 GMT
To: Nigel Houghton <>

Hi Nigel,

Wireshark box has been used by sys-admin and that directly connected to mirrored port. They use that box to monitor traffic. I am totally unaware about whether they dump the data or they use it in real time.
But to make snort working I can ask them to do it.

On Sun, May 24, 2009 at 8:16 PM, Nigel Houghton <>wrote:

> On Sat, May 23, 2009 at 4:04 PM, Stephen Mullins
> <> wrote:
> > I would suggest you use Sguil with Snort and you can launch wireshark
> > from Sguil if needed.
> >
> > Or you could use an inline network TAP on the cable running from the
> > SPAN port to the Wireshark box to "split" the signal so it goes to
> > both the Snort sensor and the Wireshark box.
> >
> > Steve Mullins
> >
> > On Tue, May 19, 2009 at 12:01 PM, Sadanand Ghagare <>
> wrote:
> >> Hi
> >>
> >> We are in process to implement snort as network sensor in our network.
> But
> >> problem here is, we already have wireshark machine connected to
> monitoring
> >> port of switch and we don't want to disturb existing setup.
> >> So whether it is possible to integrate snort with wireshark so that
> snort
> >> can analyze the packets captured by wireshark as per snort rule base.
> >> If yes, how to configure it.
> >> I hope I am up to the point for my requirements.
> Ignoring all the drawbacks of using a windows box for this, I have to
> know exactly what the wireshark instance is doing? Is someone really
> looking at the data? Is wireshark being used to dump out all traffic
> so that someone can go back and look at it later? Is someone watching
> it real time?
> --
> Nigel Houghton
> Head Mentalist
> &&
-- Thanks & Regards Sadanand G.

------------------------------------------------------------------------------ Register Now for Creativity and Technology (CaT), June 3rd, NYC. CaT is a gathering of tech-side developers & brand creativity professionals. Meet the minds behind Google Creative Lab, Visual Complexity, Processing, & iPhoneDevCamp asthey present alongside digital heavyweights like Barbarian Group, R/GA, & Big Spaceship.

_______________________________________________ Snort-users mailing list Go to this URL to change user options or unsubscribe: Snort-users list archive: