Snort mailing list archives

Tying alerts to hostnames?


From: "Scott Phippen" <ScottPhippen () vitalworks com>
Date: Mon, 17 Jun 2002 15:05:32 -0500


Is it possible for Snort to resolve and log the hostname in addition to the
IP address at the time an alert is triggered? On a network where IPs leases
are changing as workstations come on and off the network, logging just the
IP makes it difficult to trace back alerts (in particular some of the
policy.rules) to the correct workstation. If not, maybe someone could offer
some suggestions on how they are tying the alerts to particular
users/workstations in a DHCP environment where leases change frequently.
Thanks in advance!!!

Running Snort 1.8.3/MySQL 3.23.43/Acid 0.9.6b17 on Win2000.

Scott



_______________________________________________________________

Sponsored by:
ThinkGeek at http://www.ThinkGeek.com/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: