Snort mailing list archives
Re: Rules and sensor management
From: Nigel Houghton <nhoughton () sourcefire com>
Date: Mon, 8 Feb 2010 16:15:35 -0500
On Mon, Feb 8, 2010 at 4:00 PM, Paul Schmehl <pschmehl_lists () tx rr com> wrote:
I'm looking for something that can manage rules and conf files on multiple sensors. I do *not* want something that automagically fetches the vrt rules and uses oinkmaster to maintain the rules, because that's not what I'm doing on these particular sensors. I looked at IDS Policy Manager, which looked promising (even though it's written for Windows only), but the dang thing doesn't work. I can't browse to my hard drive and load my existing rules, conf file and other files. It doesn't have to be a dumbed down GUI. Buehler???? -- Paul Schmehl, Senior Infosec Analyst As if it wasn't already obvious, my opinions are my own and not those of my employer. ******************************************* "It is as useless to argue with those who have renounced the use of reason as to administer medication to the dead." Thomas Jefferson ------------------------------------------------------------------------------ The Planet: dedicated and managed hosting, cloud storage, colocation Stay online with enterprise data centers and the best network in the business Choose flexible plans and management services without long-term contracts Personal 24x7 support from experience hosting pros just a phone call away. http://p.sf.net/sfu/theplanet-com _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Like cvs or subversion or similar? How about rsync? A package maybe? Might help if you actually stated what it is you are trying to do *exactly*, if it were me I'd be using pulled pork or oinkmaster and pointing it to a local master server. I might also look into doing rsync for local boxes too, so I could ensure the same rules/configs go to the appropriate boxes. -- Nigel Houghton Head Mentalist SF VRT http://vrt-sourcefire.blogspot.com && http://www.snort.org/vrt/ ------------------------------------------------------------------------------ The Planet: dedicated and managed hosting, cloud storage, colocation Stay online with enterprise data centers and the best network in the business Choose flexible plans and management services without long-term contracts Personal 24x7 support from experience hosting pros just a phone call away. http://p.sf.net/sfu/theplanet-com _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Rules and sensor management Paul Schmehl (Feb 08)
- Re: Rules and sensor management Nigel Houghton (Feb 08)
- Re: Rules and sensor management Paul Schmehl (Feb 09)
- Re: Rules and sensor management Tim Clarkson (Feb 09)