in reply to Re^2: Help with Snort and File::Tail
in thread Help with Snort and File::Tail

He is suggesting that if snort were to be configured to send output its output to stdout*, your script could act like a filter (like grep), so you wouldn't have to use File::Tail and the process would be more reliable.

You'd still have to identify alerts, thought.

* — I'm not familiar with snort. This could be trivial or impossible.