Snort & email

From: Dan S Baxter (Dan.Baxter_at_ipaper.com)
Date: 05/04/05

  • Next message: Jason Patel: "Re: Value of IDS, ROI"
    To: focus-ids@securityfocus.com
    Date: Wed, 4 May 2005 10:16:37 -0500
    
    

    I'm setting up a Snort sensor in our environment and I am unable to
    determine how I might get emailed on alerts. I understand some are using
    Swatch, but we are not logging to syslogs but rather to a mysql db. What
    are others doing in this case?

    If I can't get it to alert me, it doesn't do me as much good, as I do not
    have the time to watch it 24/7.

    Dan Baxter
    International Paper
    Information Risk Management
    901-419-5193

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: Jason Patel: "Re: Value of IDS, ROI"

    Relevant Pages

    • Re: How to monitor server performance
      ... When I came into my current environment, ... morning healthcheck reports and real time alerts in a small to medium ... provide alerts for hosts that have fallen off the network, ... Morning healthcheck reports will pass ...
      (comp.unix.solaris)
    • Re: How to monitor server performance
      ... When I came into my current environment, ... morning healthcheck reports and real time alerts in a small to medium ... provide alerts for hosts that have fallen off the network, ... Morning healthcheck reports will pass ...
      (comp.unix.solaris)
    • Process store.exe and memory consumption
      ... I keep getting this error in my alerts: ... The store.exe process is allocating more memory than usually. ... The environment is Exchange2003 on SBS2003Pro. ...
      (microsoft.public.exchange.admin)