Snort mailing list archives
new unified2 parser - requesting logs
From: Paul Meserve <pmeserve () gmail com>
Date: Wed, 27 May 2009 12:22:07 +0100
We're developing a new open source log parser for snort unified2 logs, written in ruby. Our goal is to provide easy access to the actual structured data inside the logs for analysis or export (to a database or other central log store, with whatever schema you choose) If anyone has examples of "real world" unified2 logs they'd be willing to share with us, we'd very much appreciate it for purposes of testing the library's speed and compatibility issues with normal datasets If you have logs you could send, please e-mail me directly. If the log is under 20MB you can attach it to the email, otherwise a URL to it would be appreciated. Let me know your platform and version of snort as well, and also if you'd be willing for snippets of the log to be included in the unit tests for the parser(i.e. released open source) Thanks! We'll announce when a ruby gem for the parser is available --- Paul Meserve http://adminmyserver.com ------------------------------------------------------------------------------ Register Now for Creativity and Technology (CaT), June 3rd, NYC. CaT is a gathering of tech-side developers & brand creativity professionals. Meet the minds behind Google Creative Lab, Visual Complexity, Processing, & iPhoneDevCamp as they present alongside digital heavyweights like Barbarian Group, R/GA, & Big Spaceship. http://p.sf.net/sfu/creativitycat-com _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- new unified2 parser - requesting logs Paul Meserve (May 27)