Skip to content
Discussion options

You must be logged in to vote

They are in steno format. You can covert them to PCAP either via the GUI front end (Via Dashboard/Alerts/Ect)

Or you can use: so-pcap-export
https://docs.securityonion.net/en/2.3/stenographer.html?highlight=pcap%20export

You would need to know a bit about the pcap you are exporting, using stenoquery (info like x Hours/minutes before, X hours/minutes after, or hard dates.

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@yula-21
Comment options

@xfaith
Comment options

@yula-21
Comment options

@xfaith
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants