He is suggesting that if snort were to be configured to send output its output to stdout*, your script could act like a filter (like grep), so you wouldn't have to use File::Tail and the process would be more reliable.
You'd still have to identify alerts, thought.
* — I'm not familiar with snort. This could be trivial or impossible.
In reply to Re^3: Help with Snort and File::Tail
by ikegami
in thread Help with Snort and File::Tail
by ahuang14
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |