[Snort-users] Sending Alert Via E-mail

Jason Haar Jason.Haar at ...294...
Mon Nov 5 14:46:05 EST 2001


On Mon, Nov 05, 2001 at 12:21:09PM +0800, Fadzly Zainuddin wrote:
> How can I send any attempt via e-mail. I'm running snork  on Redhat 7.0.

Swatch is your friend:

A /etc/swatchrc rule like:

watchfor / snort:.*TELNET root login/
 echo
 exec /usr/local/bin/swatchlogger -snort security at ...294... 'IDS Event' $*

... would trigger "swatchlogger" whenever someone logged into a root account
via telnet.

What "swatchlogger" is is of course your problem :-)

-- 
Cheers

Jason Haar

Information Security Manager
Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417




More information about the Snort-users mailing list