in reply to Re: Re: Snort
in thread Snort output; report changes only?
store the length of file in a temporary file, and then use
that as the offset to seek into the file next time. If it
doesn't put you back at the end of the file, then read all
the new entries... then store the new length for the next
check.
Just make sure you check the return from the seek, as the
log file may have been rotated between runs... in that case
just read from the begining.