Snort mailing list archives

Re: Snort->OSSIM Sensor only, unified2?


From: "Dewhirst, Rob" <robdewhirst () gmail com>
Date: Wed, 11 Jan 2012 13:44:00 -0600

Oh I suppose that would be helpful.  :)

OSSIM 3.1. Ubuntu 10.0.4 LTS amd64 for the sensor.

On Wed, Jan 11, 2012 at 11:10 AM, Tudor Panaitescu <TPanaitescu () colorcon com
wrote:

Hi Rob
Can you please provide some details, like OS, version, ossim version etc. ?

Thanks,
Tudor

[image: Inactive hide details for "Dewhirst, Rob" ---01/11/2012 12:02:23
PM---Can anyone share any documentation they have for getting]"Dewhirst,
Rob" ---01/11/2012 12:02:23 PM---Can anyone share any documentation they
have for getting a snort sensor (only a sensor) pushing unif

From: "Dewhirst, Rob" <robdewhirst () gmail com>
To: snort-users () lists sourceforge net,
Date: 01/11/2012 12:02 PM
Subject: [Snort-users] Snort->OSSIM Sensor only, unified2?
------------------------------



Can anyone share any documentation they have for getting a snort
sensor (only a sensor) pushing unified2 logs to a remote OSSIM
console?

I found some fragments of instructions on the alienware forums and I
got the ossim-agent up and running on the sensor and connecting back
to the OSSIM server, but it's not sending any events. (and I know
events are occuring because I send them to another snorby server).


------------------------------------------------------------------------------
Ridiculously easy VDI. With Citrix VDI-in-a-Box, you don't need a complex
infrastructure or vast IT resources to deliver seamless, secure access to
virtual desktops. With this all-in-one solution, easily deploy virtual
desktops for less than the cost of PCs and save 60% on VDI infrastructure
costs. Try it free! http://p.sf.net/sfu/Citrix-VDIinabox
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest
Snort news!


----------------------
Colorcon - Your Formulation Partner

Visit us at http://www.colorcon.com
Colorcon is committed to energy conservation and to the reduction of
waste. Please consider the environment before you print this e-mail.

"This e-mail may contain information that is confidential or privileged.
If you are not the intended recipient, do not use, print or distribute
this e-mail or any attachments. Please notify the sender and delete the
e-mail and any attachments. Thank you."



------------------------------------------------------------------------------
Ridiculously easy VDI. With Citrix VDI-in-a-Box, you don't need a complex
infrastructure or vast IT resources to deliver seamless, secure access to
virtual desktops. With this all-in-one solution, easily deploy virtual
desktops for less than the cost of PCs and save 60% on VDI infrastructure
costs. Try it free! http://p.sf.net/sfu/Citrix-VDIinabox
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest
Snort news!

------------------------------------------------------------------------------
Ridiculously easy VDI. With Citrix VDI-in-a-Box, you don't need a complex
infrastructure or vast IT resources to deliver seamless, secure access to
virtual desktops. With this all-in-one solution, easily deploy virtual 
desktops for less than the cost of PCs and save 60% on VDI infrastructure 
costs. Try it free! http://p.sf.net/sfu/Citrix-VDIinabox
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: