Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 5.3 How do I Up: 5 Getting Fancy Previous: 5.1 I hear people

5.2 How do I process those Snort logs into reports?

  1. Barnyard 5.1 can be used to process unified output files into a number of formats, including output to a database for further analysis.
  2. SnortSnarf, a tool for producing HTML out of snort alerts for navigating through these alerts.

    http://www.silicondefense.com/snortsnarf/

  3. If you want to set up logging to a database you could try ACID. Some documentation describing the current ACID functionality includes:

    http://www.cert.org/kb/acid/

  4. You can manipulate the unified output files directly without a separate database and browse/correlate them with Cerebus:

    http://dragos.com/cerebus/

  5. For GUI front ends with simple log browsing, look at:


next up previous
Next: 5.3 How do I Up: 5 Getting Fancy Previous: 5.1 I hear people