Snort mailing list archives

Re: Pulled Pork


From: k vijay sai prashanth <vijaysaiprashanth () gmail com>
Date: Tue, 30 Oct 2012 14:19:59 +0530

So basically there is a 30 day trial during which you can only update the
rules once 15 minutes? Isn't that a reasonable enough amount of time? How
much is small amount that you are referring to? I wanted to install
PulledPork for the IDS installed for my organization. Is this an annual
amount?

Also about installing a front-end for my snort. What is the ideal
database architecture when dealing with multiple sensors. Does each sensor
have its own database or do all the sensors log events to a common database
server on which the front-end software [like snorby or aanval] is installed
or is there any other way this is implemented.

Please advice.

Regards,
Prashanth

On Mon, Oct 29, 2012 at 7:49 PM, JJ Cummings <cummingsj () gmail com> wrote:

Good call

Sent from the iRoad

On Oct 29, 2012, at 8:18, "Michael Steele" <michaels () winsnort com> wrote:

Don’t forget to tell him that another drawback of not being a paid
subscriber is that pulledPork can ONLY be ran once every 15 minutes, to
grab new rules. So if you have a failed download after 1 second, you’ll
have to wait 15 minutes before you can try again. This even applies to
downloading directly from the website.****

** **

Kindest regards,****

Michael...****

** **

WINSNORT.com Management Team Member****

--****

****************** Established ~ 2001 ***********************

*          Visit Us @ http://www.winsnort.com           *****

*      ~~ FREE WinIDS Snort installation guides ~~      *****

*               ~~ FREE support forums ~~               *****

* Snort: Open Source Network IDS - http://www.snort.org *****

*************************************************************

** **

*From:* JJC [mailto:cummingsj () gmail com <cummingsj () gmail com>]
*Sent:* Monday, October 29, 2012 9:35 AM
*To:* k vijay sai prashanth
*Cc:* snort-users () lists sourceforge net
*Subject:* Re: [Snort-users] Pulled Pork****

** **

You can get a free (30 day old rules) registered user feed or pay a small
fee and get immediately up-to-date rules vie the subscriber feed.  Info for
both is found here: http://www.snort.org/snort-rules/****

** **

JJC****

On Mon, Oct 29, 2012 at 6:23 AM, k vijay sai prashanth <
vijaysaiprashanth () gmail com> wrote:****

Hello All,****

** **

I would like to install and have a functional Pulled port to automatically
update my rules. Do I have to pay anything for this? I read somewhere that
I need to login to snort.org and generate an Oinkcode to properly
configure PulledPork. Is there any documentation on how this can be
performed? Please advice.****

** **

Thanks and Regards,
Prashanth****



------------------------------------------------------------------------------
The Windows 8 Center - In partnership with Sourceforge
Your idea - your app - 30 days.
Get started!
http://windows8center.sourceforge.net/
what-html-developers-need-to-know-about-coding-windows-8-metro-style-apps/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest
Snort news!****

** **


------------------------------------------------------------------------------
Everyone hates slow websites. So do we.
Make your web apps faster with AppDynamics
Download AppDynamics Lite for free today:
http://p.sf.net/sfu/appdyn_sfd2d_oct
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: