Snort mailing list archives
SnortDB schema vs. Snort XML schema.
From: "patrick.n.fitzgerald.1" <pfitzge1 () purdue edu>
Date: Mon, 11 Jun 2001 09:30:45 -0500 (EST)
Hello all, I've noticed that the two data models (snortDB and Snort XML) are not compatible, at least according to the most recent (release) documentations. Also, I've noticed that the XML output by snort is not valid according to the DTD at http://www.cert.org/DTD/snml-1.0.dtd (contains "option" element which is not listed in DTD) , and that the DTD itself looks a little bit strange (it has a duplicate ELEMENT? I thought this was against the spec...) The project I'm working on (CERIAS IRDB https://www.cerias.purdue.edu/irdb/ ) is trying to support snort, but we would really like to avoid reinventing as many wheels as possible. There are security concerns within our organization (and hopefully many others) with respect to giving just anyone access to the DB server, so we are trying to implement a module in our database to receive XML formatted alerts from snort via https into the database, where both our DB and the ACID package will be able to make use of the data. Are there any plans to make the two data models more similar or at the very least more self-consistent soon? I could probably kludge something together to make one schema fit inside the other, but if this work is already being done elsewhere I would rather not duplicate the effort. Any information you can give will be appreciated. Thanks, Patrick Fitzgerald CERIAS IRDB Project -- "BUGS Flood pinging the broadcast address is not recommended." -- ping(1) _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- SnortDB schema vs. Snort XML schema. patrick.n.fitzgerald.1 (Jun 11)
- Re: SnortDB schema vs. Snort XML schema. Jed Pickel (Jun 15)