Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Users
[Top] [All Lists]

RE: [Snort-users] Snort reports

Subject: RE: [Snort-users] Snort reports
Date: Wed, 15 Feb 2006 14:43:11 -0500
If you look at the base code specifically base_stat_*.php and
base_qry_main.php you can see the sql statements base is using to query
stuff like the "Most Frequent 15 addresses". From there you could build your
query to suit your needs.

  _____  

From: snort-users-admin@lists.sourceforge.net
[mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of Pablo Sanchez
Sent: Wednesday, February 15, 2006 1:20 PM
To: Snort-users@lists.sourceforge.net
Subject: [Snort-users] Snort reports


Hi guys,

I know that almost everybody uses ACID, BASE and so on to check the snort
logs and alerts. But I'm needing to develop my own interface for the snort
database. 
So I'd like to know if someone has already made some reports using the
database. 
I'm searching for SQL statements to make my own reports. 
Example: Top 15 alerts, Top 15 services, Top 15 IP address attacked, and so
on...

I'm also taking a look at the database schema. (
http://www.andrew.cmu.edu/user/rdanyliw/snort/snortdb/snortdb_schema.html ).

Best regards, 

Pablo

Attachment: smime.p7s
Description: S/MIME cryptographic signature

<Prev in Thread] Current Thread [Next in Thread>