DaemonLogger

From NSMWiki
Jump to: navigation, search

DaemonLogger is a new, fast packet logger designed specifically for use in NSM environments. The author, Marty Roesch, also wrote Snort, so you know the code is solid. The main page is here, and you can read a good description of using it in high-speed ring-buffer mode here.

You may find this post from Richard Bejtlich helpful for replacing snort with Daemonlogger:

http://sourceforge.net/mailarchive/forum.php?thread_name=120ef0530704030738h1ec03dc0nd9a9e53f9c4922cf%40mail.gmail.com&forum_name=sguil-devel