Snort mailing list archives

Snort reports


From: Pablo Sanchez <petduo () gmail com>
Date: Wed, 15 Feb 2006 18:19:32 +0000

Hi guys,

I know that almost everybody uses ACID, BASE and so on to check the snort
logs and alerts. But I'm needing to develop my own interface for the snort
database.
So I'd like to know if someone has already made some reports using the
database.
I'm searching for SQL statements to make my own reports.
Example: Top 15 alerts, Top 15 services, Top 15 IP address attacked, and so
on...

I'm also taking a look at the database schema. (
http://www.andrew.cmu.edu/user/rdanyliw/snort/snortdb/snortdb_schema.html ).

Best regards,

Pablo

Current thread: