in reply to Re: Re: Snort
in thread Snort output; report changes only?

store the length of file in a temporary file, and then use that as the offset to seek into the file next time. If it doesn't put you back at the end of the file, then read all the new entries... then store the new length for the next check. Just make sure you check the return from the seek, as the log file may have been rotated between runs... in that case just read from the begining.