[Snort-users] Any HOWTO for merging separate snort IDS's into central DB?
Jason.Haar at ...294...
Tue Dec 17 16:09:06 EST 2002
For network protection we're running snort on separate boxes with local
MySQL databases. However, once a month (say) I'd like to pull those SQL logs
together into a "meta-DB" so that we can look at the IDS network as a whole.
Obviously snort on these standalone systems are re-using the same id numbers
for different things, so I was wondering if anyone had written a script that
could allow such separate databases to be pulled together as a consistent
offering. All our snort systems run the same release and same schema, so
there data is internally consistent.
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1
More information about the Snort-users