Any news on Snort and remote syslog servers?
cubert last edited by
Searching forums I found back in Febuary 2007 some asked about send snort alerts to syslog server. At that time it was not supported, do we know if anyone was able to get this to work?
blak111 last edited by
Is there a method to to this that you found?
cybrsrfr last edited by
I've done it with a new package I finished building yesterday called PHP Service.
You can read more about from the following links.
In the wiki snort example I added the following lines for your benefit. If you only want to log the Snort alert to the syslog then comment out or remove the lines that are between 'begin close session' and 'end close session.'
//– begin close session --------------
//-- end close session --------------
Hope this helps.