Question when parsing snort log files
"Perrymon, Josh L." <[email protected]> Wed, 12 Nov 2003 16:49:10 -0600
| Newsgroups | gmane.comp.security.ids.snort.snarf |
|---|---|
| Message-ID | <5E1F351F4AE1D611A7FE00B0D0AB064A01B2A464@is6b> |
I have snort logging to a directory under my webroot..... Snort is logging into sub directories with IP addresses.... example--- www/snort ( directory ) 1.1.1.1 2.2.2.2 3.3.3.3 snort.alert It seems that snort snarf has problems parsing the alerts under the IP address sub directories.. Any ideas on what I'm doing wrong? Thanks! Joshua Perrymon Sr. Network Security Consultant BE&K Information Security Dept. 2000 International Park Drive Birmingham, Al 35243 Voice ( 205 ) 972-6745