Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




honeypots logo Honeypots mailing list archives

Re: Alerting
From: "George Chamales" <george () overt org>
Date: Mon, 31 Mar 2003 17:29:56 -0600 (CST)

Richard,

We're currently using swatch to email out alerts based on outbound
connections/rate-limiting events seen from the firewall.  Syslog-ng is
being used to ferry them from the data-control machine to our logging
host.

Our config scripts are posted at:
http://honeynet.overt.org/index.php/Network-Based%20Monitoring

These are for swatch version 3.0.4 although looking at
http://swatch.sourceforge.net

there appears to be a new version.

Best of luck,

george






  By Date           By Thread  

Current thread:
  • Re: Alerting George Chamales (Mar 31)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]