Wireshark & SIEM
I have Wireshark on a port listenting - can I get it to periodically send syslog messages to a SIEM about the nature (stats per protocoll etc.) and volume of traffic encountered?
regards, Georg
I have Wireshark on a port listenting - can I get it to periodically send syslog messages to a SIEM about the nature (stats per protocoll etc.) and volume of traffic encountered?
regards, Georg
I guess you could by cobbling something together with scripts and tshark, but note that a continuously running Wireshark or tshark tends to run out of memory due to retained state and that Wireshark is really a packet analyser not a network monitoring tool, there are other tools specifically for that task.
Please start posting anonymously - your entry will be published after you log in or create a new account.
Asked: 2017-12-14 17:43:28 +0000
Seen: 1,943 times
Last updated: Dec 14 '17
Wireshark 2.4.1 GTK Crash on long run
Why redirection of VoIP calls to voicemail fails?
Capture incoming packets from remote web server
How do I get and display packet data information at a specific byte from the first byte?
Client is waiting for FIN flag from server for 30 sec
wifi disconnects as wireshark starts
How do I add "child item" to an item in the subtree?
What is the syntax for wireshark custom column
Getting error MSB4018 when trying to build wireshark sources