Skip to content
Discussion options

You must be logged in to vote

First, it's important to note that we were simply using tcpdump temporarily to verify traffic on the interface. Once you start receiving traffic and start generating alerts, then you shouldn't really need to run tcpdump after that.

Second, please note that Security Onion does not configure or control tcpdump in any way.

It sounds like what you are describing is default behavior for tcpdump. From the tcpdump man page at https://www.tcpdump.org/manpages/tcpdump.1.html (emphasis added):

-i interface
--interface=interface
Listen, report the list of link-layer types, report the list of time stamp types, or report the results of compiling a filter expression on interface. If unspecified and if…

Replies: 3 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@dougburks
Comment options

Comment options

You must be logged in to vote
1 reply
@dougburks
Comment options

Answer selected by AB00-sys
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants