|
-
June 25th, 2002, 07:16 PM
#12
Well, if you set snort to log to syslog(for *nix), you can use swatch or logcheck to monitor the log and mail you under certain conditions.
It is possible to run snort on win32 platforms, binaries are available here
http://www.snort.org/dl/binaries/
Maybe there is a utility available for windows which could take care of the notification, I dont know.
Also, you could set snort to log to mysql, and find a script or something which will periodically check for new additions to the database, and mail those to you.
Also, there is something called ACID which is an analysis console for snort, basically a webpage, I suppose you could use that remotely, although Im not sure you would really want it set up that way as now your IDS box would have to make services available from the internet and that could lead to a compromised IDS box.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|