Use swatch to generate e-mail alerts in Snort
I currently have Snort installed on Slackware 9.1 using MySQL and Acid. I don't know of a way to have Acid automatically send alerts via e-mail. What is the best way to get this done?
When you register, my team of editors will also send you resources covering Linux administration and management; integration and interoperability between Linux, Windows and Unix; securing Linux and mixed-platform environments; and migrating to Linux.
Margie Semilof, Editorial Director
ACID has limited e-mail functionality. The best and most flexible solution
will be to use the "swatch" tool to generate e-mail upon certain alerts from
Snort. Many sample configuration files for "swatch" are available on the
Web (e.g.
http://project.honeynet.org/papers/honeynet/swatchrc.txt).
Dig Deeper
-
People who read this also read...
This was first published in July 2004