On Thu, May 13, 2010 at 1:59 PM, John Jasen <[email protected]> wrote:
>
> We have one network tap available, and want to put various tools on it
> that use libpcap to pull from the network cards.
>
> Is there a way to set up one PCAP instance, dump that to a buffer, and
> have stuff like snort, ntop and dnsiff pull from the buffer?

I never saw a response to your note.   Is there some reason that the
-C, -w, and perhaps -W options won't work
with the tcpdump command?  Just point the appropriate tool at the
appropriate file.  Delete the old ones as required.

Bill Bogstad
_______________________________________________
Tech mailing list
[email protected]
http://lopsa.org/cgi-bin/mailman/listinfo/tech
This list provided by the League of Professional System Administrators
 http://lopsa.org/

Reply via email to