> Anyone have used Bro and Snort together to the same live traffic? You could give packet-bricks a shot: https://github.com/bro/packet-bricks It requires netmap, however. You'd use a Duplicator brick to split up the traffic over two pipes. Matthias