[Bro] read trace offline

Seth Hall hall.692 at osu.edu
Mon Nov 2 06:20:03 PST 2009


On Nov 2, 2009, at 8:33 AM, antonionestola_ at libero.it wrote:

> Hi,I have a stupid question:Can I do an offline-analysis with Bro of  
> a trace file in pcap form?thank you..


The Bro binary has the "-r" option similar to tcpdump for reading in  
pcap formatted tracefiles.

   .Seth

---
Seth Hall
Network Security - Office of the CIO
The Ohio State University
Phone: 614-292-9721




More information about the Bro mailing list