[Snort-users] Snort reports

Hartman, Shane SHARTMAN at ...13482...
Wed Feb 15 11:45:02 EST 2006


If you look at the base code specifically base_stat_*.php and
base_qry_main.php you can see the sql statements base is using to query
stuff like the "Most Frequent 15 addresses". From there you could build your
query to suit your needs.

  _____  

From: snort-users-admin at lists.sourceforge.net
[mailto:snort-users-admin at lists.sourceforge.net] On Behalf Of Pablo Sanchez
Sent: Wednesday, February 15, 2006 1:20 PM
To: Snort-users at lists.sourceforge.net
Subject: [Snort-users] Snort reports


Hi guys,

I know that almost everybody uses ACID, BASE and so on to check the snort
logs and alerts. But I'm needing to develop my own interface for the snort
database. 
So I'd like to know if someone has already made some reports using the
database. 
I'm searching for SQL statements to make my own reports. 
Example: Top 15 alerts, Top 15 services, Top 15 IP address attacked, and so
on...

I'm also taking a look at the database schema. (
http://www.andrew.cmu.edu/user/rdanyliw/snort/snortdb/snortdb_schema.html ).

Best regards, 

Pablo

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20060215/85523052/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3678 bytes
Desc: not available
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20060215/85523052/attachment.bin>


More information about the Snort-users mailing list