[Snort-users] GUI for snort

Jeremy Hoel jthoel at ...11827...
Wed Oct 10 17:22:30 EDT 2012


It really depends on your workflow.  Snorby would probably be easiest
to get up and running.. Sguil takes more time and has more moving
parts.  Some people just send alerts to a SEIM tool (splunk, OSSIM,
Arcsite, etc..)

Beyond that.. for consoles only.. it's spares.  There's S.O. and Red
Border, but those are both all in one type solutions..

I did see a new project come through another list..  SNEZ, but I
haven't tried it yet.
http://sourceforge.net/projects/snez/?goback=%2Egde_2570760_member_173579066



On Wed, Oct 10, 2012 at 9:16 PM, Leonardo Pezente <lmpezente at ...11827...> wrote:
> If BASE is dead now, what is an another GUI good for the job now? I have
> read a post about that, so, im think on change to other GUI, but im not sure
> what i should use.
> ------------------------------------------------------------------------------
> Don't let slow site performance ruin your business. Deploy New Relic APM
> Deploy New Relic app performance management and know exactly
> what is happening inside your Ruby, Python, PHP, Java, and .NET app
> Try New Relic at no cost today and get our sweet Data Nerd shirt too!
> http://p.sf.net/sfu/newrelic-dev2dev
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>
> Please visit http://blog.snort.org to stay current on all the latest Snort
> news!




More information about the Snort-users mailing list