Re: Prelude and Sguil capabilities
Yoann Vandoorselaere <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <1164101396.30617.95.camel@arwen> |
On Tue, 2006-11-21 at 10:02 +0100, Robin Gruyters wrote: > Quoting Yoann Vandoorselaere <[email protected]>: > > On Fri, 2006-11-10 at 16:42 +0100, Robin Gruyters wrote: > >> - Save full packets in tcpdump format; (which we already have > >> up-and-running) > > > > Modifying Snort so that it attach the full packet data, and having > > Prewikka able to print the headers (as is currently done, but > > differently) potentially sound like a good idea. > > > > Did you actually tried it? If you did, I'd like to hear about it. > > > Well like I said, we already have this done, but we have done it with > tcpdump(8) not with Snort. I don't like the idea to use Snort for > Alerts as well for full packet logging. (e.g. security issues with > Snort) Could you elaborate ? > >> - Add more external command; (p0f, tcpdump, etc) > > > > Since Prewikka 0.9.7, you can run any command out of Prewikka, so you > > might want to check this out. > > > What arguments are possible to use with the external command? Only > $host? I can't find any documentation about this... It's described in the Prewikka template configuration file: [host_commands] # # You can use the $host variable that will be substituted with # the source/target host value. # #MyCommand: /path/to/command <parameters> #Command Title: /usr/bin/test -x $host -a If you need more substitution parameters, feel free to suggest them on trac.prelude-ids.com. Regards, -- Yoann Vandoorselaere <[email protected]> _______________________________________________ Prelude-devel site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-devel