Snort mailing list archives
Re: SIEM
From: Da Beave <dabeave () gmail com>
Date: Fri, 27 Mar 2015 08:32:15 -0400
Look into Sagan (http://sagan.io)., it integrates nicely with Snorby. On Mar 11, 2015 6:46 AM, "Sharif Uddin" <Sharif.Uddin () spectrumgeo com> wrote:
Hello I would like to know if I can use snort + snorby + barnyard2 to achieve something simialir to http://www.solarwinds.com/log-event-manager.aspx My ideal goal is to monitor what users are doing in the domain, specifically access/modiy files/folders on network on linux shares. Also the usual vpn connection active sync, logins, unusual activity etc. Sharif Uddin *Development/Support Engineer* ------------------- *Spectrum Geo Ltd* Dukes Court, Duke Street Woking, Surrey GU21 5BH UNITED KINGDOM Tel: +44 (0) 1483 730201 Fax: +44 (0) 1483 762620 www.spectrum*asa*.com <http://www.spectrumasa.com/> ------------------------------------------------------------------------------ Dive into the World of Parallel Programming The Go Parallel Website, sponsored by Intel and developed in partnership with Slashdot Media, is your hub for all things parallel software development, from weekly thought leadership blogs to news, videos, case studies, tutorials and more. Take a look and join the conversation now. http://goparallel.sourceforge.net/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
------------------------------------------------------------------------------ Dive into the World of Parallel Programming The Go Parallel Website, sponsored by Intel and developed in partnership with Slashdot Media, is your hub for all things parallel software development, from weekly thought leadership blogs to news, videos, case studies, tutorials and more. Take a look and join the conversation now. http://goparallel.sourceforge.net/
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- SIEM Sharif Uddin (Mar 11)
- Re: SIEM Da Beave (Mar 27)