Hi Andre, I wrote sometime ago this paper "Building an active response IDS with OSSEC/Snort"
http://www.dynsec.com.br/arquivos/ossec-snort-activeresponse_english.pdf Hope it helps! Regards, On Wed, Jun 17, 2009 at 3:28 PM, Andre Pawlowski<[email protected]> wrote: > > Hi guys. > > I just installed snort and tested it. Now I had the idea to combine it > with ossec. So I read a little bit in the wiki and saw that the rules > > 20300 - 20499 IDS (Snort specific) > > are for snort. But I can't find them in the ossec/rules directory. I > used the latest stable version of ossec (ossec 2). Are there any rules > for the /var/log/snort/alert logfile? Has anyone of you ossec that take > a look to the snort logfiles running? Which log format I must enter in > the ossec.conf when I configure the position of the snort logfile? > > Thanks in advance. > > -- > > Andre Pawlowski > > ------------------------------------------------------------------- > > Amerikas Verbündete müssen bei jedem neuen Präsidenten lernen, was für die > nächsten vier oder acht Jahre das Gute und das Böse ist - ein anstrengender > Prozess. > -Carl Friedrich von Weizsäcker > > -- Rodrigo Montoro (Sp0oKeR) http://www.spooker.com.br http://www.snort.org.br http://www.linkedin.com/in/spooker YSTS 3.0 - June 22nd, 2009 - http://ysts.org
