Snort mailing list archives
Sendig alerts to another system
From: pierangelo motta <pierangelo_motta () yahoo it>
Date: Tue, 9 Mar 2004 17:23:21 +0100 (CET)
Hi all, my first post.. forgive my english and any dumb question.. so.. I got snort up and runnig, with mysql and acid. It works fine :) The problem is I have to mail alerts to another system because I usually won't access the NIDS. It should be the NIDS to contact me. I made a script so the NIDS can connect to another machine(via ftp) on internet and (auto)update rules. Another to let me know if snort's alive.. But how can it send me everyday alerts? I'd like to have alerts in a tcpdump format( I read it's much better, isn't it?). The only place where snort logs alerts is the database, and I was not able to make snort log alert in a file(that tcpdump or ethereal could read) too. Better turn off databasse? And log using something like this? snort -c snort.conf -i eth0 -g snort -D -b -l var/log/snort -L my_alert_file -A full Then NIDS will mail me "my_alert_file".. If you want to know anything more.. thank you in advance. Pierangelo ______________________________________________________________________ Yahoo! Mail: 6MB di spazio gratuito, 30MB per i tuoi allegati, l'antivirus, il filtro Anti-spam http://it.yahoo.com/mail_it/foot/?http://it.mail.yahoo.com/ ------------------------------------------------------- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies. Learn everything from fundamentals to system administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Sendig alerts to another system pierangelo motta (Mar 09)