Snort mailing list archives
RE: Snort reports
From: "Hartman, Shane" <SHARTMAN () thezenith com>
Date: Wed, 15 Feb 2006 14:43:11 -0500
If you look at the base code specifically base_stat_*.php and base_qry_main.php you can see the sql statements base is using to query stuff like the "Most Frequent 15 addresses". From there you could build your query to suit your needs. _____ From: snort-users-admin () lists sourceforge net [mailto:snort-users-admin () lists sourceforge net] On Behalf Of Pablo Sanchez Sent: Wednesday, February 15, 2006 1:20 PM To: Snort-users () lists sourceforge net Subject: [Snort-users] Snort reports Hi guys, I know that almost everybody uses ACID, BASE and so on to check the snort logs and alerts. But I'm needing to develop my own interface for the snort database. So I'd like to know if someone has already made some reports using the database. I'm searching for SQL statements to make my own reports. Example: Top 15 alerts, Top 15 services, Top 15 IP address attacked, and so on... I'm also taking a look at the database schema. ( http://www.andrew.cmu.edu/user/rdanyliw/snort/snortdb/snortdb_schema.html ). Best regards, Pablo
Attachment:
smime.p7s
Description:
Current thread:
- Snort reports Pablo Sanchez (Feb 15)
- Re: Snort reports Kevin Johnson (Feb 15)
- Re[2]: Snort reports Mathieu CHATEAU (Feb 18)
- Re: Re[2]: Snort reports Kevin Johnson (Feb 18)
- Re[4]: Snort reports Mathieu CHATEAU (Feb 19)
- Re[2]: Snort reports Mathieu CHATEAU (Feb 18)
- Re: Snort reports Kevin Johnson (Feb 15)
- <Possible follow-ups>
- RE: Snort reports Hartman, Shane (Feb 15)