<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Snort -&gt; Dump Payload]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto"><s>I'd like to have more information included in Snorts alerts, such as HTTP GET or POST for example.<br />
Is it possible to log HTTP-Requests, or package payload in general? Where does snort store the dumped payload?</s></p>
<p dir="auto">Is the only way to analyze the pcap-files to download them via ssh/scp?</p>
<p dir="auto">Best regards<br />
Thomas</p>
]]></description><link>https://forum.netgate.com/topic/113606/snort-dump-payload</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Apr 2026 00:08:31 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/113606.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 27 Mar 2017 11:11:54 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Snort -&gt; Dump Payload on Thu, 06 Apr 2017 23:53:43 GMT]]></title><description><![CDATA[<p dir="auto">In additoin to scp, you can download the PCAPs via the webgui Services-&gt;Snort-&gt;Alerts, Alert Log Actions: Download</p>
<p dir="auto">But if the alert file gets too big it can cause the php process to crash and you may have to resort back to scp.</p>
]]></description><link>https://forum.netgate.com/post/691808</link><guid isPermaLink="true">https://forum.netgate.com/post/691808</guid><dc:creator><![CDATA[jeffhammett]]></dc:creator><pubDate>Thu, 06 Apr 2017 23:53:43 GMT</pubDate></item></channel></rss>