Hi Daniel, I'm referring to running netsniff-ng, having it accept ERSPAN data, and write the decapsulated data to a pcap file.
Thanks, Doug On Tue, Oct 22, 2013 at 4:23 AM, Daniel Borkmann <dbork...@redhat.com> wrote: > On 10/21/2013 05:00 PM, Doug Burks wrote: >> >> Hello all, >> >> Have you considered implementing support for decoding ERSPAN? Looks >> like gulp and snort currently support this: > > > Are you referring to the packet dissector or to store the decapsulated > data to a pcap file? > > >> http://staff.washington.edu/corey/gulp/ >> http://blog.snort.org/2013/07/snort-295-is-now-available.html >> >> Thanks for your consideration! >> > -- Doug Burks http://securityonion.blogspot.com -- You received this message because you are subscribed to the Google Groups "netsniff-ng" group. To unsubscribe from this group and stop receiving emails from it, send an email to netsniff-ng+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/groups/opt_out.