Re: Prelude and Sguil capabilities

Yoann Vandoorselaere <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <1164101396.30617.95.camel@arwen>
On Tue, 2006-11-21 at 10:02 +0100, Robin Gruyters wrote:
> Quoting Yoann Vandoorselaere <[email protected]>:
> > On Fri, 2006-11-10 at 16:42 +0100, Robin Gruyters wrote:
> >> - Save full packets in tcpdump format; (which we already have
> >>   up-and-running)
> >
> > Modifying Snort so that it attach the full packet data, and having
> > Prewikka able to print the headers (as is currently done, but
> > differently) potentially sound like a good idea.
> >
> > Did you actually tried it? If you did, I'd like to hear about it.
> >
> Well like I said, we already have this done, but we have done it with  
> tcpdump(8) not with Snort. I don't like the idea to use Snort for  
> Alerts as well for full packet logging. (e.g. security issues with  
> Snort)

Could you elaborate ?

> >> - Add more external command; (p0f, tcpdump, etc)
> >
> > Since Prewikka 0.9.7, you can run any command out of Prewikka, so you
> > might want to check this out.
> >
> What arguments are possible to use with the external command? Only  
> $host? I can't find any documentation about this...

It's described in the Prewikka template configuration file:

[host_commands]
#
# You can use the $host variable that will be substituted with
# the source/target host value.
#
#MyCommand: /path/to/command <parameters>
#Command Title: /usr/bin/test -x $host -a

If you need more substitution parameters, feel free to suggest them on
trac.prelude-ids.com.

Regards,

-- 
Yoann Vandoorselaere <[email protected]>

_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.