Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 6.3 How do I Up: 6 Getting Fancy Previous: 6.1 I hear people

6.2 How do I process those Snort logs into reports?

  1. Barnyard 5.1 can be used to process unified output files into a number of formats, including output to a database for further analysis.
  2. SnortSnarf, a tool for producing HTML out of snort alerts for navigating through these alerts.

  3. If you want to set up logging to a database you could try ACID. Some documentation describing the current ACID functionality includes:

    http://www.cert.org/kb/acid/

  4. You can manipulate the unified output files directly without a separate database and browse/correlate them with Cerebus:

    http://dragos.com/cerebus/

  5. For GUI front ends with simple log browsing, look at:


next up previous
Next: 6.3 How do I Up: 6 Getting Fancy Previous: 6.1 I hear people
Nigel Houghton 2006-10-02