Snort mailing list archives

RE: Snort, Windows 2000 - running external program on alert.


From: "Hicks, John" <JHicks () JUSTICE GC CA>
Date: Fri, 20 Dec 2002 14:04:11 -0500

DOH! my bad, sorry :)

-----Original Message-----
From: Ueli Kistler [mailto:iuk () gmx ch]
Sent: Friday, December 20, 2002 2:05 PM
To: Hicks, John
Cc: Snort-Users (E-mail)
Subject: Re: [Snort-users] Snort, Windows 2000 - running external
program on alert.


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

IDScenter can execute any script/program you want if an alert was detected.
E-Mail support is built-in.. more features are available: log rotation, 
AutoBlock plugins, Configurations wizard for Snort, etc.
More information on www.packx.net.

Regards,
    Eclipse
    eclipse () packx net
    www.packx.net

- --

Hicks, John wrote:

IDSCenter has built-in email functionality, but not 'any' program. If
you're
looking for run x if y is found, try doing it via syslog output.

hth,
John

-----Original Message-----
From: Brian Strickland [mailto:brians () south-com com]
Sent: Friday, December 20, 2002 12:35 PM
To: 'snort-users () lists sourceforge net'
Subject: [Snort-users] Snort, Windows 2000 - running external program on
alert.


is there a way directly from snort to run an external program when an alert
is generated or indirectly (reviewing log file or sql database) to run an
external program when a alert occurs.  Like send an email, pager program,
etc. 

Brian Strickland



-------------------------------------------------------
This SF.NET email is sponsored by:  The Best Geek Holiday Gifts!
Time is running out!  Thinkgeek.com has the coolest gifts for
your favorite geek.   Let your fingers do the typing.   Visit Now.
T H I N K G E E K . C O M        http://www.thinkgeek.com/sf/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


-------------------------------------------------------
This SF.NET email is sponsored by:  The Best Geek Holiday Gifts!
Time is running out!  Thinkgeek.com has the coolest gifts for
your favorite geek.   Let your fingers do the typing.   Visit Now.
T H I N K G E E K . C O M        http://www.thinkgeek.com/sf/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


 


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQE+A2oZad+bo3Jl9EkRAoasAKC+EzXFO0Bk8alWVypcCDhQ5qeveACbBJ0K
t904ROF+ggXRjYhznTxsbas=
=bXyj
-----END PGP SIGNATURE-----


-------------------------------------------------------
This SF.NET email is sponsored by:  The Best Geek Holiday Gifts!
Time is running out!  Thinkgeek.com has the coolest gifts for
your favorite geek.   Let your fingers do the typing.   Visit Now.
T H I N K G E E K . C O M        http://www.thinkgeek.com/sf/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: