Snort mailing list archives

RE: Sending Alert Via E-mail


From: Kresna Prawira <kprawira () esurance com>
Date: Mon, 5 Nov 2001 15:15:40 -0800

how about for windows NT machines? 

-----Original Message-----
From: Jason Haar [mailto:Jason.Haar () trimble co nz]
Sent: Monday, November 05, 2001 2:45 PM
To: 'Snort-users () lists sourceforge net'
Subject: Re: [Snort-users] Sending Alert Via E-mail


On Mon, Nov 05, 2001 at 12:21:09PM +0800, Fadzly Zainuddin wrote:
How can I send any attempt via e-mail. I'm running snork  on Redhat 7.0.

Swatch is your friend:

A /etc/swatchrc rule like:

watchfor / snort:.*TELNET root login/
 echo
 exec /usr/local/bin/swatchlogger -snort security () trimble co nz 'IDS Event'
$*

... would trigger "swatchlogger" whenever someone logged into a root account
via telnet.

What "swatchlogger" is is of course your problem :-)

-- 
Cheers

Jason Haar

Information Security Manager
Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: