[Bro] Bro and Snort together

Matthias Vallentin vallentin at icir.org
Sun Oct 18 09:20:40 PDT 2015


> Anyone have used Bro and Snort together to the same live traffic?

You could give packet-bricks a shot:

    https://github.com/bro/packet-bricks

It requires netmap, however. You'd use a Duplicator brick to split up
the traffic over two pipes.

    Matthias


More information about the Bro mailing list