Hello, I can get bro to read dump captures without any problems... >bro -r <capture.file> mt ... but I'm not quite sure on the live traffic Do I type ">bro -i eth0" ? Thanks, Bryan Florida Tech