Snort mailing list archives

Re: Snort frontends?


From: Ueli Kistler <iuk () gmx ch>
Date: Thu, 20 Mar 2003 00:22:47 +0100

IDScenter 1.1 RC3 will feature a MySQL log output in html which is e-mail / viewable on local computer (customisable (and multiple) queries are allowed). This will make it easy to configure in many different ways (i also programmed a fast multi-threaded DNS resolver for this).. And much more (oinkmaster support, autoblock support mysql (there is a real chance that i'm doing this before the release), etc..)

Release: when it's done (of course)

Regards,
 Ueli Kistler
 eclipse () packx net
 www.packx.net

--

Paul Schmehl wrote:

On Wed, 2003-03-19 at 16:40, Gordon Cunningham wrote:
How about using the log as well as MySQL and tail -f the log file in a
terminal window?  About as real-time as you can get.

Yeahbut.....we're looking for something that will present *summarized
and collated* realtime data in a GUI interface (HTTP is fine) for
viewing by several people (for example, Cisco's IDS only allows one of
us to view it at a time) *and* things like the ability to email or page
for specific alerts - without having to cobble together six different
pieces as presently seems to be the norm.

I'm a big fan of automating as much as possible so computers do the
grunt work and people can do the high level overview, decision-making
stuff.

I love my job, but I do sleep sometimes.  :-)





-------------------------------------------------------
This SF.net email is sponsored by: Does your code think in ink? You could win a Tablet PC. Get a free Tablet PC hat just for playing. What are you waiting for?
http://ads.sourceforge.net/cgi-bin/redirect.pl?micr5043en
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: