Snort mailing list archives

Re: Rules and sensor management


From: Nigel Houghton <nhoughton () sourcefire com>
Date: Mon, 8 Feb 2010 16:15:35 -0500

On Mon, Feb 8, 2010 at 4:00 PM, Paul Schmehl <pschmehl_lists () tx rr com> wrote:
I'm looking for something that can manage rules and conf files on multiple
sensors.  I do *not* want something that automagically fetches the vrt rules
and uses oinkmaster to maintain the rules, because that's not what I'm doing on
these particular sensors.

I looked at IDS Policy Manager, which looked promising (even though it's
written for Windows only), but the dang thing doesn't work.  I can't browse to
my hard drive and load my existing rules, conf file and other files.

It doesn't have to be a dumbed down GUI.

Buehler????

--
Paul Schmehl, Senior Infosec Analyst
As if it wasn't already obvious, my opinions
are my own and not those of my employer.
*******************************************
"It is as useless to argue with those who have
renounced the use of reason as to administer
medication to the dead." Thomas Jefferson


------------------------------------------------------------------------------
The Planet: dedicated and managed hosting, cloud storage, colocation
Stay online with enterprise data centers and the best network in the business
Choose flexible plans and management services without long-term contracts
Personal 24x7 support from experience hosting pros just a phone call away.
http://p.sf.net/sfu/theplanet-com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



Like cvs or subversion or similar?

How about rsync?

A package maybe?

Might help if you actually stated what it is you are trying to do
*exactly*, if it were me I'd be using pulled pork or oinkmaster and
pointing it to a local master server. I might also look into doing
rsync for local boxes too, so I could ensure the same rules/configs go
to the appropriate boxes.

-- 
Nigel Houghton
Head Mentalist
SF VRT
http://vrt-sourcefire.blogspot.com && http://www.snort.org/vrt/

------------------------------------------------------------------------------
The Planet: dedicated and managed hosting, cloud storage, colocation
Stay online with enterprise data centers and the best network in the business
Choose flexible plans and management services without long-term contracts
Personal 24x7 support from experience hosting pros just a phone call away.
http://p.sf.net/sfu/theplanet-com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: