Snort mailing list archives

Snort alerts and extra information


From: Kanan Alkanan via Snort-users <snort-users () lists snort org>
Date: Wed, 20 Sep 2017 04:36:00 +0000

I am using snort to detect some bad traffic in our system, however, I need to add more information to the logged alerts 
such as to which tenant the attacker's ip address belongs, the network id? Assuming I have multiple tenant however all 
private ips are duplicated over tenants, so it is not possible to tell which node cause the attack, so I am thinking to 
include the tenant id, network id which are unique to each tenant and then attach the private ip of attacker to the 
proper tenant. Current snort alerts will not provide these information, any help will be appreciated!


Can I modify snort.conf for this
_______________________________________________
Snort-users mailing list
Snort-users () lists snort org
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: