[Snort-users] Sending Alert Via E-mail

Kresna Prawira kprawira at ...3243...
Mon Nov 5 15:16:03 EST 2001


how about for windows NT machines? 

-----Original Message-----
From: Jason Haar [mailto:Jason.Haar at ...294...]
Sent: Monday, November 05, 2001 2:45 PM
To: 'Snort-users at lists.sourceforge.net'
Subject: Re: [Snort-users] Sending Alert Via E-mail


On Mon, Nov 05, 2001 at 12:21:09PM +0800, Fadzly Zainuddin wrote:
> How can I send any attempt via e-mail. I'm running snork  on Redhat 7.0.

Swatch is your friend:

A /etc/swatchrc rule like:

watchfor / snort:.*TELNET root login/
 echo
 exec /usr/local/bin/swatchlogger -snort security at ...294... 'IDS Event'
$*

... would trigger "swatchlogger" whenever someone logged into a root account
via telnet.

What "swatchlogger" is is of course your problem :-)

-- 
Cheers

Jason Haar

Information Security Manager
Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417

_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users




More information about the Snort-users mailing list