Snort mailing list archives
Re: Email alerts
From: Matt Kettler <mkettler () evi-inc com>
Date: Mon, 07 Apr 2003 14:44:09 -0400
Read the fine FAQ for the basic suggestion: http://www.snort.org/docs/faq.html#5.7In a bit more detail, swatch/logcheck are tools which search logs for various substrings and run external scripts when they find those strings. You should be able to use the priority field as a part of your search condition.
Swatch has a homepage here: http://swatch.sourceforge.net/ At 10:21 AM 4/7/2003 -0700, Sudhakar Gummadi wrote:
Hi,This might have been answered numerous times, Sorry for asking the same question.I have installed snort the latest one on linux 8.0 recently with other required applications (mysql, apache, php and acid).I basically want to get emails ONLY on critical alerts. How would I configure ? any documentation would be really helpful Any suggestions is great appreciated.
-------------------------------------------------------This SF.net email is sponsored by: ValueWeb: Dedicated Hosting for just $79/mo with 500 GB of bandwidth! No other company gives more support or power for your dedicated server
http://click.atdmt.com/AFF/go/sdnxxaff00300020aff/direct/01/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Email alerts Sudhakar Gummadi (Apr 07)
- <Possible follow-ups>
- Re: Email alerts Matt Kettler (Apr 07)
- Re: Email alerts Erek Adams (Apr 08)