Snort mailing list archives

OT(Sorta): Querying acid/snort db from third party software


From: "Jason" <snort-users () tcpipbitch net>
Date: Tue, 27 May 2003 11:15:52 -0400 (EDT)

Sorry for the most likely offtopic post, but the acid list does not appear
to see to much traffic.

I am currently testing a third party application that pulls in data from
many different sources and then presents the coralated <spelling?> to the
user.  It currently takes in snort data via syslog and there agent,
however it does not include the payload data.  There is the option to call
external applications, which is what I am planning on doing. I was unable
to find any info on supplying arguments directly to the acid_qry_main.php
to call the search directly from the command line (using lynx in this case
for now) ie: 'lynx http://acid.blah.com/acid_qry_main.php?<some argument
to supply an IP, or a port, or whatever>'

Otherwise I will have to go the custom script route.. and my scripting
abilities are well... horrible. (currently using pgsql as backend in case
someone else has a query script I could use) :)


-------------------------------------------------------
This SF.net email is sponsored by: ObjectStore.
If flattening out C++ or Java code to make your application fit in a
relational database is painful, don't do it! Check out ObjectStore.
Now part of Progress Software. http://www.objectstore.net/sourceforge
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: