What I am upto?
1)I am using inotifytools to watch on var/log/snort dir 2) as soon as new log file generated in this dir, I add it to a pipe with a shell script. 3) this shell script gives me newly added line(new packet) to that log file which looks something like this 0600 0108 0006 0400 01c4 6e1f 11b3 99c0
What I want?
How can I create new pcap file with only this packet? 0600 0108 0006 0400 01c4 6e1f 11b3 99c0
Why I want it? The above created pcap file I will use to give input to dpkt.pcap.Reader to get details about that packet