Thanks for everyone's suggestions and contributions, even if we were not able to include the changes so far. Changes in SnortSnarf version 050314.1 (from 021111.1) ------------------------------------------------------ * Changed hard coded reference links to the Snort.org SID database to reflect changes to snort.org - MFR Changes in SnortSnarf version 021111.1 (from 021024.1) ------------------------------------------------------ + fixed some file newline problems in last distribution (reported by Robert Young) + fixed a compatibility problem with Win32 (reported by different people) + alerts with original packet included now have both sets of ports and first set of IPs as links Changes in SnortSnarf version 021024.1 (from 021017.1) ------------------------------------------------------ + fixed bug which caused SnortSnarf to hang forever if no output directory was given or if it was relative (reported by Wes Dorale) + fixed a couple compatibility problems with Win32 (reported by different people) + added -obfuscateip option to change the IP addresses in alerts to randomly (but consistently) chosen alternates (not presently available for database input) + updated -usage text and Usage file Changes in SnortSnarf version 021017.1 (from 020516.1) ------------------------------------------------------ + Updated parsing for Snort 1.9.0 full alert files + works around bug in which sometimes there is no blank line between alerts [thanks to Tomoyuki Murakami for the contrib] + works around bug in which there is sometimes an extraneous blank line in the middle of an alert (e.g., after NEXT LINK MTU) + now understands Xref sections in the form '[Xref => system id]' + removes any '\0' (^@) that was at the end of lines (e.g., at the end of ADMINISTRATIVELY PROHIBITED HOST FILTERED lines) + new-style Spade reports now processed (Spade version 021008.1 and on) + spp_portscan2 log files now processed (these entries are displayed somewhat prettified) + updated linking to ICMP log files; this involved updates for new ICMP header format in Snort 1.9.0 + more robust recognition of non-packet alerts in different formats (these get ignored) + clarified warning about unknown ICMP type text and added repeat warning suppression (you'll now only get a warning about a particular string twice) + arachNIDS reference URLs now are to www.whitehats.com instead of whitehats.com + McAfee reference URL updated + SnortSnarf will now ignore lines beginning with '#' between alerts, so you can use that to begin a comment Changes in SnortSnarf version 020516.1 (from 020316.1) ------------------------------------------------------ + SnortSnarf can now read from a Snort Mysql database; the SnortDBInput module is written and maintained by Ed Davison (Ed.Davison@bus.utexas.edu) + new -mintime=