Whenever ntop is started with the --create-suspicious-packets option active, the previous ntop-suspicious-pkts.xxxx.pcap file is overwritten with a new empty file. Considering the purpose of the file, would appending to the existing file be more appropriate?
Tim
<<attachment: winmail.dat>>
