Any news on Snort and remote syslog servers?
-
Searching forums I found back in Febuary 2007 some asked about send snort alerts to syslog server. At that time it was not supported, do we know if anyone was able to get this to work?
Cubert
-
Is there a method to to this that you found?
-
I've done it with a new package I finished building yesterday called PHP Service.
You can read more about from the following links.
http://forum.pfsense.org/index.php/topic,13775.0.html
http://doc.pfsense.org/index.php/PHPServiceIn the wiki snort example I added the following lines for your benefit. If you only want to log the Snort alert to the syslog then comment out or remove the lines that are between 'begin close session' and 'end close session.'
//– begin close session --------------
//-- end close session --------------Hope this helps.