LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 01-17-2006, 03:10 AM   #1
logicalfuzz
Member
 
Registered: Aug 2005
Distribution: Arch Linux
Posts: 291

Rep: Reputation: 48
Relate snort logs with Internal IPs


hi,
I am using snort. The alerts always show me 'our' public IPs conversing with the 'other' public IPs. While analysing i need to refer the firewall logs to relate and find the actual user (private IP) who is causing the alert. Is there a way to automatically relate these two, i.e. the firewall (PIX) logs and the Snort alerts? Something that works with snort, in short, to give something more useful.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
snort 2.4.1 (inline IPS) +shorewall 2.4.x where best to insert the QUEUE in iptables Emmanuel_uk Linux - Security 5 10-18-2005 06:48 AM
Loads of samba logs for external IPs!!!! birkinshawc Linux - Software 1 06-12-2004 12:27 PM
Separated internal IPs for hardware router jecelis Linux - Networking 2 12-06-2003 05:04 PM
snort logs get flooded iceman47 Linux - Security 2 06-04-2003 04:36 PM
What do these snort logs mean? tarballedtux Linux - Security 1 08-31-2002 10:15 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 12:12 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration