-
Hi, |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 4 replies
-
They are in steno format. You can covert them to PCAP either via the GUI front end (Via Dashboard/Alerts/Ect) Or you can use: so-pcap-export You would need to know a bit about the pcap you are exporting, using stenoquery (info like x Hours/minutes before, X hours/minutes after, or hard dates. |
Beta Was this translation helpful? Give feedback.
They are in steno format. You can covert them to PCAP either via the GUI front end (Via Dashboard/Alerts/Ect)
Or you can use: so-pcap-export
https://docs.securityonion.net/en/2.3/stenographer.html?highlight=pcap%20export
You would need to know a bit about the pcap you are exporting, using stenoquery (info like x Hours/minutes before, X hours/minutes after, or hard dates.