Logging Application Traffic


You want to log all traffic that belongs to a particular application.


Make use of the session keyword that was introduced in Recipe 2.n.


If your application, like most do, uses a particular port on a particular machine, write a rule that detects this and use the session keyword to record it. For example, to record all traffic to and from a MySQL server running on TCP 3306 on a particular machine (, for example), use the following rule:

alert tcp any any <> 3306 (msg: "MySQL"; session: all;)


See Also

