Re: Snort & email

From: James Riden (j.riden_at_massey.ac.nz)
Date: 05/08/05

  • Next message: Jose Maria Lopez Hernandez: "Re: Snort & email"
    To: "Dan S Baxter" <Dan.Baxter@ipaper.com>
    Date: 08 May 2005 10:46:25 +1200
    
    

    "Dan S Baxter" <Dan.Baxter@ipaper.com> writes:

    > I'm setting up a Snort sensor in our environment and I am unable to
    > determine how I might get emailed on alerts. I understand some are using
    > Swatch, but we are not logging to syslogs but rather to a mysql db. What
    > are others doing in this case?

    I'm logging to /var/log/snort/alert and /portscan.log as well as
    postgresql. Then I have a couple of perl scripts which do
    post-processing, including paging me if necessary. You could easily do
    the same with email, depending on how often you want to be
    emailed. There are also packages such as 'snort-stat' which can give
    you a summary of events, etc.

    In this environment, snort generates way too many alerts to email/page
    me on each one. Typically I'd only be using paging for attempted-admin
    and successful-admin type alerts.

    cheers,
     Jamie

    -- 
    James Riden / j.riden@massey.ac.nz / Systems Security Engineer
    GPG public key available at: http://www.massey.ac.nz/~jriden/
    This post does not necessarily represent the views of my employer.
    --------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from 
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    --------------------------------------------------------------------------
    

  • Next message: Jose Maria Lopez Hernandez: "Re: Snort & email"

    Relevant Pages

    • Re: Log filtering in ZAP3?
      ... I'm aware of the "Alerts & Logging" tab, ... >>someone trying to hack port 1234, you could customize the logging to ... >>find this feature. ...
      (comp.security.firewalls)
    • Re: ZAPro not creating log file
      ... >> In the Alert Events do you have some events checked for logging? ... >> Are you actually getting any alerts displayed by ZAP? ... > alerts but not keeping them in a log file. ... > I will try archiving less frequently but cannot see it making any ...
      (comp.security.firewalls)
    • Re: ZAPro not creating log file
      ... > In the Alert Events do you have some events checked for logging? ... > Are you actually getting any alerts displayed by ZAP? ... alerts but not keeping them in a log file. ...
      (comp.security.firewalls)
    • Re: Snort & email
      ... > determine how I might get emailed on alerts. ... > Swatch, but we are not logging to syslogs but rather to a mysql db. ... > Find out quickly and easily by testing it with real-world attacks from ... > CORE IMPACT. ...
      (Focus-IDS)
    • Re: ZAPro not creating log file
      ... >> settings for logs and archiving. ... logging is enabled and set to archive every day but all the log file ... Are you actually getting any alerts displayed by ZAP? ...
      (comp.security.firewalls)