Snort mailing list archives

Snort and barnyard status


From: TIannotti () checkfree com
Date: Mon, 8 Nov 2004 09:58:19 -0500

Message: 1
From: Sean Brown <sblinux () shaw ca>
To: snort-users () lists sourceforge net
Subject: Re: [Snort-users] Snort and barnyard status
Date: Fri, 5 Nov 2004 21:03:17 -0700

On November 4, 2004 1:15 pm, Lance Boon wrote:
What I'm looking for is an easy for users other than myself (in
particular my boss) to be able to look at a webpage and determine the
status of a particular snort sensor if the snort and barnyard processes
are running. I'm not sure of the best way to handle this right now what
..snip..

I run snort on my firewall, which is a OpenBSD machine. I use Net-SNMP 
to 
monitor both. There is a simple line in the snmpd.conf to tell it what 
process to monitor, and how many should be running (min/max). You can 
then 
configure traps to send and alert you if any of them die if you wish to. 
Any 
..snip..

Big Brother (http://www.bb4.org/) also works very well for this, and once 
set up is a great framework for monitoring many other aspects, including 
graphing trends.



-------------------------------------------------------
This SF.Net email is sponsored by:
Sybase ASE Linux Express Edition - download now for FREE
LinuxWorld Reader's Choice Award Winner for best database on Linux.
http://ads.osdn.com/?ad_id=5588&alloc_id=12065&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: