IDS mailing list archives

RE: Snort


From: "Eric Hines" <eric.hines () appliedwatch com>
Date: Fri, 1 Oct 2004 09:25:20 -0500

Another option is the Applied Watch Command Center, we currently support
Snort, Snort-Inline, and other open source tools such as LaBrea Tarpit.
Currently there are over 20 different report templates that we provide all
inside a cross-platform, browserless GUI. 

Check out screenshots and more information at http://www.appliedwatch.com 


Best Regards,

Eric Hines, GCIA, CISSP
Applied Watch Technologies, Inc.
http://www.appliedwatch.com
Direct: (877) 262-7593 x327
1134 N. Main St.
Algonquin, IL 60102 




-----Original Message-----
From: Jose Maria Lopez [mailto:jkerouac () bgsec com] 
Sent: Wednesday, September 29, 2004 3:09 PM
To: focus-ids () securityfocus com
Subject: Re: Snort

El lun, 27 de 09 de 2004 a las 23:09, Jeremy Gonzales escribió:
Hi,

Does anyone have experience with snort reports? How do you deal with 
the loads of information? Is there a way to  generate reports that 
eliminate the false positives? Any help will be appreciated.

Thanks,

Jeremy.

I think the best way to treat with snort generated data it's using the ACID
console, but you can't generate good reports with it. You can try
snortreport that maybe suits you better.

--
Jose Maria Lopez Hernandez
Director Tecnico de bgSEC
jkerouac () bgsec com
bgSEC Seguridad y Consultoria de Sistemas Informaticos http://www.bgsec.com
ESPAÑA

The only people for me are the mad ones -- the ones who are mad to live, mad
to talk, mad to be saved, desirous of everything at the same time, the ones
who never yawn or say a commonplace thing, but burn, burn, burn like
fabulous yellow Roman candles.
                -- Jack Kerouac, "On the Road"


--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE
IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to
learn more.
--------------------------------------------------------------------------



--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
--------------------------------------------------------------------------


Current thread: