[Snort-users] Rules and sensor management

Tim Clarkson timothyclarkson at ...125...
Tue Feb 9 19:34:44 EST 2010


I use Management software from Endace which is a commerical solution. They allow you to manage your own snort installation (custom built probe) but also provide hardware probes as well.

 

This is a commerical solution and not an open source solution, so I am not sure if this is what you are after.  

 

If you want more information please feel free to email directly.

 

Regards

------------------------------------------ 
System Management Consulting Limited 
Timothy Clarkson  
Personal: Timothy.J.Clarkson at ...11827... 
Snort List: TimothyClarkson at ...125... 
New Zealand 
 ------------------------------------------ 



 
> Date: Tue, 9 Feb 2010 14:05:49 -0600
> From: pschmehl_lists at ...14358...
> To: snort-users at lists.sourceforge.net
> Subject: Re: [Snort-users] Rules and sensor management
> 
> I will take the resounding thud in response to this question to mean that there 
> are no other options out there.
> 
> --On Monday, February 08, 2010 15:00:21 -0600 Paul Schmehl 
> <pschmehl_lists at ...14358...> wrote:
> 
> > I'm looking for something that can manage rules and conf files on multiple
> > sensors. I do *not* want something that automagically fetches the vrt rules
> > and uses oinkmaster to maintain the rules, because that's not what I'm doing
> > on these particular sensors.
> >
> > I looked at IDS Policy Manager, which looked promising (even though it's
> > written for Windows only), but the dang thing doesn't work. I can't browse
> > to my hard drive and load my existing rules, conf file and other files.
> >
> > It doesn't have to be a dumbed down GUI.
> >
> > Buehler????
> 
> 
> 
> -- 
> Paul Schmehl, Senior Infosec Analyst
> As if it wasn't already obvious, my opinions
> are my own and not those of my employer.
> *******************************************
> "It is as useless to argue with those who have
> renounced the use of reason as to administer
> medication to the dead." Thomas Jefferson
> 
> 
> ------------------------------------------------------------------------------
> SOLARIS 10 is the OS for Data Centers - provides features such as DTrace,
> Predictive Self Healing and Award Winning ZFS. Get Solaris 10 NOW
> http://p.sf.net/sfu/solaris-dev2dev
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
 		 	   		  
_________________________________________________________________
Looking for a place to manage all your online stuff? Download the new Windows Live 
http://download.live.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20100210/e9c47062/attachment.html>


More information about the Snort-users mailing list