Re: Prelude and Sguil capabilities
Yoann Vandoorselaere <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <1164107529.30617.102.camel@arwen> |
On Tue, 2006-11-21 at 11:26 +0100, Robin Gruyters wrote: > Quoting Yoann Vandoorselaere <[email protected]>: > > > On Tue, 2006-11-21 at 10:57 +0100, Robin Gruyters wrote: > >> Quoting Yoann Vandoorselaere <[email protected]>: > >> > >> > On Tue, 2006-11-21 at 10:02 +0100, Robin Gruyters wrote: > >> >> Quoting Yoann Vandoorselaere <[email protected]>: > >> >> > On Fri, 2006-11-10 at 16:42 +0100, Robin Gruyters wrote: > >> >> >> - Save full packets in tcpdump format; (which we already have > >> >> >> up-and-running) > >> >> > > >> >> > Modifying Snort so that it attach the full packet data, and having > >> >> > Prewikka able to print the headers (as is currently done, but > >> >> > differently) potentially sound like a good idea. > >> >> > > >> >> > Did you actually tried it? If you did, I'd like to hear about it. > >> >> > > >> >> Well like I said, we already have this done, but we have done it with > >> >> tcpdump(8) not with Snort. I don't like the idea to use Snort for > >> >> Alerts as well for full packet logging. (e.g. security issues with > >> >> Snort) > >> > > >> > Could you elaborate ? > >> > > >> Well in the past we had some issues with Snort that it just dies, with > >> no error messages. If you use Snort for Alerts and for full packet > >> logging, then both processes will die, so you don't have *any* alerts > >> or packet logging. That for me is a big no, no. > > > > How did it die exactly? > > > At the moment I haven't found the problem, yet. I mean was it a crash, did it froze, did it exit? What was the Snort version? Regards, -- Yoann Vandoorselaere <[email protected]> _______________________________________________ Prelude-devel site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-devel