Bluehost.com Web Hosting $6.95

[Snort-users] Multiple Sensors/Distributed Snort Config.

This is a discussion on [Snort-users] Multiple Sensors/Distributed Snort Config. within the Snort forums, part of the System Security and Security Related category; This is a multi-part message in MIME format. --===============2115122478== content-class: urn:content-classes:message Content-Type: multipart/alternative; ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-13-2006
Dan Brummer
 
Posts: n/a
Default [Snort-users] Multiple Sensors/Distributed Snort Config.

This is a multi-part message in MIME format.

--===============2115122478==
content-class: urn:content-classes:message
Content-Type: multipart/alternative;
boundary="----_=_NextPart_001_01C6A6A0.2B71A952"

This is a multi-part message in MIME format.

------_=_NextPart_001_01C6A6A0.2B71A952
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hello,
I have been a Snort user for quite some time now and I have a few
questions regarding setting up a distributed Snort system. I'm planning
to put multiple sensors on my enterprise network and have all of these
feed to a central database server. From my research I understand the
best way to do this is have each remote sensor send its Snort output
using MySQL. Is this the best way of doing this? Are there any
applications to help me with what I'm trying to do? What about the
rules and and making sure they're shared and up-to-date on all the
sensors? Do I need to be running snort on the central database server
if all it's doing is receiving sensor outputs and displaying reports
using ACID or BASE? =20
=20
Any insight on this I would greatly appreciate it.
=20
Thank you,
Dan

------_=_NextPart_001_01C6A6A0.2B71A952
Content-Type: text/html;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<META content=3D"MSHTML 6.00.2900.2912" name=3DGENERATOR></HEAD>
<BODY>
<DIV><SPAN class=3D164471117-13072006><FONT face=3DArial=20
size=3D2>Hello,</FONT></SPAN></DIV>
<DIV><SPAN class=3D164471117-13072006><FONT face=3DArial size=3D2>I have =
been a Snort=20
user for quite some time now and I have a few questions regarding =
setting up a=20
distributed Snort system.&nbsp; I'm planning to put multiple sensors on =
my=20
enterprise network and have all of these feed to a central database=20
server.&nbsp; From my research I understand the best way to do this is =
have each=20
remote sensor send its Snort output using MySQL.&nbsp; Is this the best =
way of=20
doing this?&nbsp; Are there any applications to help me with what I'm =
trying to=20
do?&nbsp; What about the rules and and making sure they're shared and =
up-to-date=20
on all the sensors?&nbsp; Do I need to be running snort on the central =
database=20
server if all it's doing is receiving sensor outputs and displaying =
reports=20
using ACID or BASE?&nbsp; </FONT></SPAN></DIV>
<DIV><SPAN class=3D164471117-13072006><FONT face=3DArial=20
size=3D2></FONT></SPAN>&nbsp;</DIV>
<DIV><SPAN class=3D164471117-13072006><FONT face=3DArial size=3D2>Any =
insight on this=20
I would greatly appreciate it.</FONT></SPAN></DIV>
<DIV><SPAN class=3D164471117-13072006><FONT face=3DArial=20
size=3D2></FONT></SPAN>&nbsp;</DIV>
<DIV><SPAN class=3D164471117-13072006><FONT face=3DArial size=3D2>Thank=20
you,</FONT></SPAN></DIV>
<DIV><SPAN class=3D164471117-13072006><FONT face=3DArial=20
size=3D2>Dan</FONT></SPAN></DIV></BODY></HTML>

------_=_NextPart_001_01C6A6A0.2B71A952--


--===============2115122478==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=...057&dat=121642

--===============2115122478==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
--===============2115122478==--

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 03:51 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0