Snort mailing list archives

new unified2 parser - requesting logs


From: Paul Meserve <pmeserve () gmail com>
Date: Wed, 27 May 2009 12:22:07 +0100

We're developing a new open source log parser for snort unified2 logs,  
written in ruby. Our goal is to provide easy access to the actual  
structured data inside the logs for analysis or export (to a database  
or other central log store, with whatever schema you choose)

If anyone has examples of "real world" unified2 logs they'd be willing  
to share with us, we'd very much appreciate it for purposes of testing  
the library's speed and compatibility issues with normal datasets

If you have logs you could send, please e-mail me directly. If the log  
is under 20MB you can attach it to the email, otherwise a URL to it  
would be appreciated. Let me know your platform and version of snort  
as well, and also if you'd be willing for snippets of the log to be  
included in the unit tests for the parser(i.e. released open source)

Thanks!

We'll announce when a ruby gem for the parser is available

---
Paul Meserve
http://adminmyserver.com

------------------------------------------------------------------------------
Register Now for Creativity and Technology (CaT), June 3rd, NYC. CaT 
is a gathering of tech-side developers & brand creativity professionals. Meet
the minds behind Google Creative Lab, Visual Complexity, Processing, & 
iPhoneDevCamp as they present alongside digital heavyweights like Barbarian 
Group, R/GA, & Big Spaceship. http://p.sf.net/sfu/creativitycat-com 
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: