Wireshark & SIEM
I have Wireshark on a port listenting - can I get it to periodically send syslog messages to a SIEM about the nature (stats per protocoll etc.) and volume of traffic encountered?
regards, Georg
I guess you could by cobbling something together with scripts and tshark, but note that a continuously running Wireshark or tshark tends to run out of memory due to retained state and that Wireshark is really a packet analyser not a network monitoring tool, there are other tools specifically for that task.
Asked: 2017-12-14 17:43:28 +0000
Seen: 2,032 times
Last updated: Dec 14 '17