Snort mailing list archives

Sendig alerts to another system


From: pierangelo motta <pierangelo_motta () yahoo it>
Date: Tue, 9 Mar 2004 17:23:21 +0100 (CET)

Hi all, my first post.. forgive my english and any
dumb question.. so..

I got snort up and runnig, with mysql and acid.
It works fine :)

The problem is I have to mail alerts to another system
because I usually won't access the NIDS.
It should be the NIDS to contact me.
I made a script so the NIDS can connect to another
machine(via ftp) on internet and (auto)update rules.
Another to let me know if snort's alive..

But how can it send me everyday alerts?
I'd like to have alerts in a tcpdump format( I read
it's much better, isn't it?).

The only place where snort logs alerts is the
database, and I was not able to make snort log alert
in a file(that tcpdump or ethereal could read) too.

Better turn off databasse? And log using something
like this?
snort -c snort.conf -i eth0 -g snort -D -b -l
var/log/snort -L my_alert_file -A full

Then NIDS will mail me "my_alert_file"..

If you want to know anything more..

thank you in advance. 
             Pierangelo


______________________________________________________________________
Yahoo! Mail: 6MB di spazio gratuito, 30MB per i tuoi allegati, l'antivirus, il filtro Anti-spam
http://it.yahoo.com/mail_it/foot/?http://it.mail.yahoo.com/


-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: