Re: Snort Monitoring

From: Larc (larc@pandora.be)
Date: 10/28/02


From: "Larc" <larc@pandora.be>
To: "Scott M. Algatt" <salgatt@turtleshell.net>, <focus-ids@securityfocus.com>
Date: Mon, 28 Oct 2002 20:23:43 +0100

Hi,

You can use SnortCenter to monitor if your remote Snort sensors are running.
Snortcenter can do alot more it's a complete webbased clent server
management system for snort.
You can find it at http://users.pandora.be/larc/

Regards,
Stefan D.
----- Original Message -----
From: "Scott M. Algatt" <salgatt@turtleshell.net>
To: <focus-ids@securityfocus.com>
Sent: Monday, October 28, 2002 2:47 PM
Subject: Snort Monitoring

> All,
>
> I am looking for something that will provide monitoring of snort for me.
> I have several remote installs of Snort 1.9 and need to find a way to
> monitor them to make sure they are operational.
>
>
> Regards,
>
> Scott M. Algatt
>
> Behold the turtle. He makes progress only when he sticks his neck out.
>
>



Relevant Pages

  • Re: Intrusion Detection Evaluation Datasets
    ... more similar to "normal" Snort rules. ... The lowest level, Triggers, are combined into Actions, which are in turn ... This means that you can monitor for SQL injection ... This means that an Action detecting an ...
    (Focus-IDS)
  • Re: Snort 101- Help
    ... configure your HOME_NET to monitor ... page 8 in SNORT documentation, ... I am not sure if Tomcat in front of Apache will interfere ... HTTP_PORT would be your port 8009, ...
    (comp.security.firewalls)
  • RES: snort- problems
    ... snort is monitoring only the ... It is important to gather some other information about your network, ... assign the "monitor port" to snort. ...
    (Focus-IDS)
  • Re: Snort Monitoring
    ... Subject: Snort Monitoring ... >> I have several remote installs of Snort 1.9 and need to find a way to ... >> monitor them to make sure they are operational. ... > Snort daemon for ya. ...
    (Focus-IDS)
  • Re: [Snort-users] instant snort sigs for new vulnerabilites
    ... Well, you can do that with snortcenter, you can adjust rules to your own ... [Snort-users] instant snort sigs for new vulnerabilites ...
    (FreeBSD-Security)