That could help me to invent my own rules. Thanks Rodrigo. It seems that no one has any snort rules ready on this mailing list. And by google searching I didn't find any rules either. So, when I have made some rules and tested it, I will post them in the OSSEC wiki that others have some rules for snort when they are searching for this.
Regards Rodrigo Montoro(Sp0oKeR) wrote: > Hi Andre, > > I wrote sometime ago this paper "Building an active response IDS with > OSSEC/Snort" > > http://www.dynsec.com.br/arquivos/ossec-snort-activeresponse_english.pdf > > Hope it helps! > > Regards, > > On Wed, Jun 17, 2009 at 3:28 PM, Andre Pawlowski<[email protected]> wrote: > >> Hi guys. >> >> I just installed snort and tested it. Now I had the idea to combine it >> with ossec. So I read a little bit in the wiki and saw that the rules >> >> 20300 - 20499 IDS (Snort specific) >> >> are for snort. But I can't find them in the ossec/rules directory. I >> used the latest stable version of ossec (ossec 2). Are there any rules >> for the /var/log/snort/alert logfile? Has anyone of you ossec that take >> a look to the snort logfiles running? Which log format I must enter in >> the ossec.conf when I configure the position of the snort logfile? >> >> Thanks in advance. >> >> -- >> >> Andre Pawlowski >> >> ------------------------------------------------------------------- >> >> Amerikas Verbündete müssen bei jedem neuen Präsidenten lernen, was für die >> nächsten vier oder acht Jahre das Gute und das Böse ist - ein anstrengender >> Prozess. >> -Carl Friedrich von Weizsäcker >> >> >> > > > > -- Andre Pawlowski ------------------------------------------------------------------- Man wird nur schlauer, wenn man gegen schlauere Gegner spielt. -Fundamentals of Chess
