On Thu, May 13, 2010 at 1:59 PM, John Jasen <[email protected]> wrote: > > We have one network tap available, and want to put various tools on it > that use libpcap to pull from the network cards. > > Is there a way to set up one PCAP instance, dump that to a buffer, and > have stuff like snort, ntop and dnsiff pull from the buffer?
I never saw a response to your note. Is there some reason that the -C, -w, and perhaps -W options won't work with the tcpdump command? Just point the appropriate tool at the appropriate file. Delete the old ones as required. Bill Bogstad _______________________________________________ Tech mailing list [email protected] http://lopsa.org/cgi-bin/mailman/listinfo/tech This list provided by the League of Professional System Administrators http://lopsa.org/
