I'll dig up the link later, but it should be very apparent on their pages (it was to me, when I was perusing).
So, I pulled up my BASE console and looked at a sample packet. To look at payload/packets within BASE, you go to a line item then click on the "ID", which would look akin to "2-278900".
BASE capture view:
Snorby capture view:
Now, if I wanted to further investigate, I can (in BASE), go to a listing, then click the offending IP (or the other IP...doesn't matter). Then I click "Unique alerts" or "Unique IP links" under "Summary Statistics":
I don't understand the argument of saying that BASE doesn't capture full payload. Of course, BASE won't. It's just a SEM. Snort would actually do the capturing. It would also totally depend on who sets up Snort and their requirements. The admin that configures Snort may not even have all the sigs enabled. But, BASE will show any payload that Snort does capture.
At this point, Snorby's search and analytical functionality is lacking. I've said this before and got ridiculed by one of the Snorby developers. We all know Snorby is relatively new when comparing it to BASE, but until the Snorby dev team enables better query functionality and better ways to quickly track activity, I'm going to stick to my guns. A pretty (and even simplified) interface is one thing, but when it comes to the meat and potatoes, candy apples doesn't cut it. As an analyst, I'd not want to lose any type of query features, as this will make a sometimes frustrating job all the more frustrating (been there, done that).
Lastly, I will NOT HAVE A PISSING MATCH over this. I've been doing such comparisons for YEARS and am fully capable of judging what is acceptable and what is not regarding most security tools (that's why I get paid the big bucks), although I'm always objective in my opinions. I definitely know what "best of breed" entails. I'm going to put it out there: Snorby is NOT best of breed. I'd love it to be, but right now, it is NOT. It has to help me sort/organize/filter information that helps me catch malware and such...much more that what it currently offers. Right now, with Snorby, there's no such thing as digging down or simplifying the search through thousands of potentially bad security events. "Packet capture options/Customer" isn't going to cut it. It is good for the small investigation but not for the bigger tasks. Let's be grown-ups about this topic and offer objective opinions. If you can't do that, don't even try to leave some nasty comment on this blog. Comments moderation is enabled. Yes, I do require clarification on what is considered "full payload analysis", as I feel that's not enough of a description and could actually be relating to something else entirely different that the above (I doubt it, though).