Suggestions for best way to get snort alerts
I currently have snort installed on slack 9.1 using mysql and acid. Since acid, to my knowledge, can not automagically send out alert via e-mail what is the best way to get this done?
The best thing I've come up with would be to search the alert log file and if an alert is there have it e-mail to me, however I don't know how to get it to not send duplicate alerts each time it searches. Any suggestions would be greatly appreciated. Thanks |
Make a cron-script which grep:s the alerts and pipe the output to the mail-command. You can also use logrotate to automagically send you the logs (there is a setting for that in /etc/logrotate).
|
Thanks for the suggestion, however if I grep out certain text how would I stop it from sending the same alerts each time it runs? I'm checking into logsurfer and swatch. Any suggestions or either of them? Thanks
|
Quote:
|
I'm sure someone already invented that wheel. Nothing in Snort.org's contrib dir like PigSentry?
|
With pigsentry how can i get it to only e-mail certain alerts? from what i can tell from the help it is going to e-mail every alert. If i log it to a log file and search the log file I have the same problem as before?
|
Dunno. If you're using a logfile I think sending mails using a state file based on either classification or SID should do.
|
Quote:
Quote:
# pigsentry -l /var/snort_log/alert -t /usr/local/pig --state-checkpoint=x This creates the pigstate file in /usr/local/pig, and from there i can set up a cron job to search the pigstate file for the alerts I am looking for and to make sure the pigstate file gets cleared out so I don't get multiple alerts I can use the --state-expire=x What I can't seem to figure out is how to only log certain alerts to the statefile? You mentioned using a state file based on classification or SID, how would I accomplish this? OT question - What do you think about the guy on Jepardy? Is he cheating? |
|
Both logsurfer and swatch should do the job nicely.
I'm also currently looking into logsurfer to check my samba log files. |
All times are GMT -5. The time now is 07:18 AM. |