Snort mailing list archives
RE: action on packet
From: "Knight, Ric" <RKnight () TUC ca>
Date: Thu, 10 Oct 2002 12:45:21 -0400
You can use the -s flag to send the alerts to syslog, and then use swatch or logcheck to monitor the syslog file and take some kind of action on the alert. -----Original Message----- From: Reinaldo Nurquez [mailto:RNurquez () etek cl] Sent: Thursday, October 10, 2002 12:20 PM To: snort-users () lists sourceforge net Subject: [Snort-users] action on packet Hello: Can I configure my rules for to do some action on the packet for example: send a mail some people about the alert, how can I configure it? Thank in advanced Best Regards Reinaldo
Current thread:
- action on packet Reinaldo Nurquez (Oct 10)
- <Possible follow-ups>
- RE: action on packet Knight, Ric (Oct 10)