Bill Bogstad wrote:
> On Thu, May 13, 2010 at 1:59 PM, John Jasen <[email protected]> wrote:
>> We have one network tap available, and want to put various tools on it
>> that use libpcap to pull from the network cards.
>>
>> Is there a way to set up one PCAP instance, dump that to a buffer, and
>> have stuff like snort, ntop and dnsiff pull from the buffer?
> 
> I never saw a response to your note.   Is there some reason that the
> -C, -w, and perhaps -W options won't work
> with the tcpdump command?  Just point the appropriate tool at the
> appropriate file.  Delete the old ones as required.

That's not a bad idea, Bill. I'll have to look into it.

-- 
-- John E. Jasen ([email protected])
-- "Deserve Victory." -- Terry Goodkind, Naked Empire
_______________________________________________
Tech mailing list
[email protected]
http://lopsa.org/cgi-bin/mailman/listinfo/tech
This list provided by the League of Professional System Administrators
 http://lopsa.org/

Reply via email to