Bro Digest, Vol 18, Issue 8

Randy,

Maybe this is easy way to get raw trace -

http://geek00l.blogspot.com/2006/12/bro-ids-enable-full-content-data.html

If you are really looking at ring buffer, daemonlogger will do.

If you are encountering any issue with bro in certain timeline and say you want to extract the data from that period, you can do the job with tcpslice.

Cheers ;]