Hi Andre,

I wrote sometime ago this paper "Building an active response IDS with
OSSEC/Snort"

http://www.dynsec.com.br/arquivos/ossec-snort-activeresponse_english.pdf

Hope it helps!

Regards,

On Wed, Jun 17, 2009 at 3:28 PM, Andre Pawlowski<[email protected]> wrote:
>
> Hi guys.
>
> I just installed snort and tested it. Now I had the idea to combine it
> with ossec. So I read a little bit in the wiki and saw that the rules
>
> 20300 - 20499 IDS (Snort specific)
>
> are for snort. But I can't find them in the ossec/rules directory. I
> used the latest stable version of ossec (ossec 2). Are there any rules
> for the /var/log/snort/alert logfile? Has anyone of you ossec that take
> a look to the snort logfiles running? Which log format I must enter in
> the ossec.conf when I configure the position of the snort logfile?
>
> Thanks in advance.
>
> --
>
> Andre Pawlowski
>
> -------------------------------------------------------------------
>
> Amerikas Verbündete müssen bei jedem neuen Präsidenten lernen, was für die 
> nächsten vier oder acht Jahre das Gute und das Böse ist - ein anstrengender 
> Prozess.
>        -Carl Friedrich von Weizsäcker
>
>



-- 
Rodrigo Montoro (Sp0oKeR)
http://www.spooker.com.br
http://www.snort.org.br
http://www.linkedin.com/in/spooker

YSTS 3.0 - June 22nd, 2009 - http://ysts.org

Reply via email to