I have been trying to figure out how top configure SNORT with the steaming server option in Mikrotik. I guess Mikrotik supports the TZSP format but I can not figure out how to get snort to accept a UDP stream in that format? I have search for the TZSP format option for SNORT and other such things but have found very little information on this. Can anyone shed some light on this?
Ok I figured out I use ./trafr -s | in some way but I dont see how to make snort listen on standard input.
OK GOT IT.
./trafr -s |/usr/sbin/snort -r -
Now I just need to play more with snort..
Thanks
Tim