Snort mailing list archives
Snort alerts and extra information
From: Kanan Alkanan via Snort-users <snort-users () lists snort org>
Date: Wed, 20 Sep 2017 04:36:00 +0000
I am using snort to detect some bad traffic in our system, however, I need to add more information to the logged alerts such as to which tenant the attacker's ip address belongs, the network id? Assuming I have multiple tenant however all private ips are duplicated over tenants, so it is not possible to tell which node cause the attack, so I am thinking to include the tenant id, network id which are unique to each tenant and then attach the private ip of attacker to the proper tenant. Current snort alerts will not provide these information, any help will be appreciated! Can I modify snort.conf for this
_______________________________________________ Snort-users mailing list Snort-users () lists snort org Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Snort alerts and extra information Kanan Alkanan via Snort-users (Sep 19)
