Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Get Snort Alerts out of pfSense for email alerting?

    Scheduled Pinned Locked Moved pfSense Packages
    7 Posts 4 Posters 7.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mevans336
      last edited by

      Hello Everyone,

      For those of you who have managed to get your Snort alerts out of pfSense and onto another machine for parsing or email alert generation, what solution have you found to be effective and reliable?

      I'm especially interested in email alert generation.

      Thanks!

      1 Reply Last reply Reply Quote 0
      • M
        mevans336
        last edited by

        Yikes, no one?

        Should I break Snort out onto its own box for enhanced functionality or is there another recommended IDS?

        1 Reply Last reply Reply Quote 0
        • J
          judex
          last edited by

          "Enhanced functionality"? At the moment it would be great , if it would work at all…

          2.1-RELEASE (amd64)
          built on Wed Sep 11 18:17:48 EDT 2013
          FreeBSD 8.3-RELEASE-p11

          1 Reply Last reply Reply Quote 0
          • M
            mevans336
            last edited by

            @judex:

            "Enhanced functionality"? At the moment it would be great , if it would work at all…

            I don't have a problem with Snort generating alerts. That part works fine for me. (Sorry, my two Snort installations work fine.)

            I'd just like to know if anyone has a scheme for getting those alerts out of pfSense and generating emails based upon them.

            1 Reply Last reply Reply Quote 0
            • K
              Koti
              last edited by

              Why dont you send the snort alerts to some external syslog server and get email alerting.

              :)

              1 Reply Last reply Reply Quote 0
              • K
                kevross33
                last edited by

                Use unified2 and barnyard in Snort package to write it off to an external database and use snorby (snorby.org) to email you reports.

                1 Reply Last reply Reply Quote 0
                • M
                  mevans336
                  last edited by

                  @kevross33:

                  Use unified2 and barnyard in Snort package to write it off to an external database and use snorby (snorby.org) to email you reports.

                  I tried this, but I could never get anything to populate in Snorby. I'll research it again.

                  You wouldn't happen to know of a good how-to on the web would you?

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.