[Snort-users] Reputation Preprocessor

Joel Esler jesler at ...1935...
Mon Oct 1 11:04:19 EDT 2012


On Oct 1, 2012, at 10:52 AM, Yonas Abebe <jonasabebe at ...11827...> wrote:

> OK. Then i have a related question. Is there a way (if any) that i can pass a black list file to snort from Mysql database at run time?

No.  The alerts that are generated will have the IP in them when the alert is logged.

I will be putting a blog post together on where you can download a blacklist that we produce here at Sourcefire for use for free in the Snort platform.

Putting some details together for publication, but should be either today or tomorrow.  Keep an eye on blog.snort.org.

--
Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
Sourcefire

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20121001/06af7511/attachment.html>


More information about the Snort-users mailing list