[Snort-users] Snort reports

Kevin Johnson kjohnson at ...12400...
Wed Feb 15 17:55:14 EST 2006

On Feb 15, 2006, at 1:19 PM, Pablo Sanchez wrote:

> Hi guys,
> I know that almost everybody uses ACID, BASE and so on to check the  
> snort logs and alerts. But I'm needing to develop my own interface  
> for the snort database.
> So I'd like to know if someone has already made some reports using  
> the database.
> I'm searching for SQL statements to make my own reports.
> Example: Top 15 alerts, Top 15 services, Top 15 IP address  
> attacked, and so on...
> I'm also taking a look at the database schema. ( http:// 
> www.andrew.cmu.edu/user/rdanyliw/snort/snortdb/snortdb_schema.html ).
> Best regards,
> Pablo


I am glad to hear that so many people use BASE.<grin>  May I ask why  
you need to create your own interface?  If it is a feature that needs  
to be added, it would probably be easier to just work with us to  
implement it?

If you still need to write your own, I would set up BASE and run it  
with the sql trace turned on.  That way it will log every query that  
is run including the dynamic ones.

Hope that helps,
BASE Project Lead
The next step in IDS analysis!

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20060215/8b1b53ea/attachment.html>

More information about the Snort-users mailing list