Video Screencast Help
Search Video Help Close Back
to help

SSIM 4.7 + Sourcefire eStreamer

Created: 13 Nov 2012 | 3 comments
Dorbian's picture
0 0 Votes
Login to vote

Hi all,

I've been swapping the Snort Syslog connector for the Sourcefire eStreamer for our sourcefire environment.

My main reason is the collection of network packets from the IDS environment.
When looking into the events received, i don't see any network packet information, any of you have an idea how to get this done ?

Cheers,

-Sven

Comments 3 CommentsJump to latest comment

Laurent_c's picture

The Source Fire collector doesn't collect the Data Payload if it is what you are looking for.

 

 

 

 

0
Login to vote
  • Actions
Dorbian's picture

Hi Laurent,

Thanks,

There is no way to configure the collector to get that data in one of the custom fields ?

Cheers,

-Sven

0
Login to vote
  • Actions
Laurent_c's picture

Well this is how the collector was written. To be able to collect the payload, it will need to be changed (either code or/and sensor) to colelct payload from the sourcefire db.

 

This is a good enhancement request.

+1
Login to vote
  • Actions