RE: Snort & email

From: Omar Herrera (oherrera_at_prodigy.net.mx)
Date: 05/07/05

  • Next message: Joel Esler: "Re: Snort & email"
    Date: Sat, 07 May 2005 09:08:32 -0500
    To: focus-ids@securityfocus.com
    
    

    Hi Dan,

    You can make snort log to both syslog and a MySQL database. Syslog alerts
    can be emailed and the will be wiped out eventually, when logs are rotated,
    so no overhead there.

    I'm not sure how much this affects performance, but have tested it this way
    and have not noticed a significant degradation.

    Regards,
    Omar Herrera

    > -----Original Message-----
    > From: Dan S Baxter [mailto:Dan.Baxter@ipaper.com]
    >
    > I'm setting up a Snort sensor in our environment and I am unable to
    > determine how I might get emailed on alerts. I understand some are using
    > Swatch, but we are not logging to syslogs but rather to a mysql db. What
    > are others doing in this case?
    >
    > If I can't get it to alert me, it doesn't do me as much good, as I do not
    > have the time to watch it 24/7.

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: Joel Esler: "Re: Snort & email"

    Relevant Pages

    • Re: [opensuse] How to monitor Linux systems from a focal/central point (was: ranting and raving abo
      ... If the syslog was really so central in enterprise real-time monitoring ... It has a main dumb terminal on a serial port, and also a serial port printer. ... The card may control instead an X.25 connection, which can be used for file transfers and some more terminals. ... They have Unix machines with expensive proprietary software that collect each report, save them into a database record, do some analysis, raise alerts based on importance... ...
      (SuSE)
    • FW: Snort, Syslog, and alert.ids (Updated)
      ... While alerts are getting written to alert.ids just fine, ... Snort initializes just fine, I suppose because the ... But it doesn't know where to send syslog ... Be sure not to specify a command line option for alerting, ...
      (Focus-IDS)
    • Re: Simultaneously write syslog to another server?
      ... c) d) See David Hart and Michael Heiming suggested. ... Snort log to syslog or send snort log and snort configured ... I'm wondering which is the best for security purposes. ...
      (comp.os.linux.security)
    • Netscreen 25 to Linux syslog
      ... Where could I find the documentation on the way the netscreen messages ... sent to syslog are written? ... I'd like to add these into a MySQL database ...
      (comp.security.firewalls)
    • Re: Netscreen 25 to Linux syslog
      ... >Where could I find the documentation on the way the netscreen messages ... >sent to syslog are written? ... >I'd like to add these into a MySQL database ...
      (comp.security.firewalls)