Snort mailing list archives

RE: Snort reports


From: "Hartman, Shane" <SHARTMAN () thezenith com>
Date: Wed, 15 Feb 2006 14:43:11 -0500

If you look at the base code specifically base_stat_*.php and
base_qry_main.php you can see the sql statements base is using to query
stuff like the "Most Frequent 15 addresses". From there you could build your
query to suit your needs.

  _____  

From: snort-users-admin () lists sourceforge net
[mailto:snort-users-admin () lists sourceforge net] On Behalf Of Pablo Sanchez
Sent: Wednesday, February 15, 2006 1:20 PM
To: Snort-users () lists sourceforge net
Subject: [Snort-users] Snort reports


Hi guys,

I know that almost everybody uses ACID, BASE and so on to check the snort
logs and alerts. But I'm needing to develop my own interface for the snort
database. 
So I'd like to know if someone has already made some reports using the
database. 
I'm searching for SQL statements to make my own reports. 
Example: Top 15 alerts, Top 15 services, Top 15 IP address attacked, and so
on...

I'm also taking a look at the database schema. (
http://www.andrew.cmu.edu/user/rdanyliw/snort/snortdb/snortdb_schema.html ).

Best regards, 

Pablo

Attachment: smime.p7s
Description:


Current thread: