<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general">
    <title>gmane.comp.security.ids.snort.general</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36722"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36721"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36720"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36719"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36718"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36717"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36716"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36715"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36714"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36713"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36712"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36711"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36710"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36709"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36708"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36707"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36706"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36705"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36704"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36703"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36722">
    <title>Re: Testing snort</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36722</link>
    <description>&lt;pre&gt;Hi Romskie,

That's great, Thanks.

AT the time of installing tcpreplay I am getting following error.

checking for libpcap... configure: error: Unable to find matching library for header file in /usr
Does anyone face this issue ever.

Regards,
Sandip

-----Original Message-----
From: Romskie L [mailto:rslaranjo&amp;lt; at &amp;gt;gmail.com] 
Sent: 25 May 2012 11:28
To: snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Cc: Sandip Bankewar
Subject: Re: [Snort-users] Testing snort

Hi Sandip,

The error says you need to install flex. If you are using ubuntu, you can apt-get install flex to install it.


Regards,

Rommel L.

On Fri, May 25, 2012 at 1:29 PM, Sandip Bankewar &amp;lt;sbankewar&amp;lt; at &amp;gt;cloudaccess.com&amp;gt; wrote:



------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. htt&lt;/pre&gt;</description>
    <dc:creator>Sandip Bankewar</dc:creator>
    <dc:date>2012-05-25T06:35:50</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36721">
    <title>Re: Testing snort</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36721</link>
    <description>&lt;pre&gt;Hi Paul,

Thanks for your help.

My intention is to test the EPS handling capacity.

This way I think we need to run same command from number of terminals right?

Sandip Bankewar


-----Original Message-----
From: Paul Halliday [mailto:paul.halliday&amp;lt; at &amp;gt;gmail.com] 
Sent: 24 May 2012 18:04
To: Nick Moore
Cc: Sandip Bankewar; snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Subject: Re: [Snort-users] Testing snort

Sounds complicated :)

Couldn't he just feed the pcap directly to snort:

snort -r &amp;lt;file.pcap&amp;gt; ?

On Thu, May 24, 2012 at 9:19 AM, Nick Moore &amp;lt;nmoore&amp;lt; at &amp;gt;sourcefire.com&amp;gt; wrote:



--
Paul Halliday
http://www.squertproject.org/



------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
___&lt;/pre&gt;</description>
    <dc:creator>Sandip Bankewar</dc:creator>
    <dc:date>2012-05-25T05:54:07</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36720">
    <title>Re: Testing snort</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36720</link>
    <description>&lt;pre&gt;Hi Sandip,

The error says you need to install flex. If you are using ubuntu, you
can apt-get install flex to install it.


Regards,

Rommel L.

On Fri, May 25, 2012 at 1:29 PM, Sandip Bankewar
&amp;lt;sbankewar&amp;lt; at &amp;gt;cloudaccess.com&amp;gt; wrote:

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Romskie L</dc:creator>
    <dc:date>2012-05-25T05:57:47</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36719">
    <title>Re: Testing snort</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36719</link>
    <description>&lt;pre&gt;Hi Nick,

Yes I have installed tcpreplay successfully on Linux. Thanks for your help.


While installing libpcap I am getting following error:

configure: error: Your operating system's lex is insufficient to compile
libpcap.  flex is a lex replacement that has many advantages, including
being able to compile libpcap.  For more information, see
http://www.gnu.org/software/flex/flex.html.

Could you please help me out.

Regards,
Sandip Bankewar

From: Nick Moore [mailto:nmoore&amp;lt; at &amp;gt;sourcefire.com]
Sent: 24 May 2012 17:50
To: Sandip Bankewar
Cc: snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Subject: Re: [Snort-users] Testing snort

Sandip,

I have only used it in Linux and Mac OSX. I have to confess that I haven't used Windows as my primary workstation for over six years and am not familiar with current tools for it. The website mentions Cygwin, which if I remember correctly creates a Linux-like environment for Windows. So you're pretty much back to square one.

If there are other users on the list who are more knowledgable re&lt;/pre&gt;</description>
    <dc:creator>Sandip Bankewar</dc:creator>
    <dc:date>2012-05-25T05:29:33</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36718">
    <title>Re: Testing snort</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36718</link>
    <description>&lt;pre&gt;Hi Joel,

Thanks for your help.
My intention for this is to test EPS handling capacity of system.

Regards,
Sandip Bankewar


-----Original Message-----
From: Joel Esler [mailto:jesler&amp;lt; at &amp;gt;sourcefire.com] 
Sent: 24 May 2012 18:03
To: Sandip Bankewar
Cc: snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Subject: Re: [Snort-users] Testing snort

Snort can read pcap files directly.

snort -c /etc/snort/conf -r &amp;lt;file.pcap&amp;gt;


Joel

On May 24, 2012, at 6:04 AM, Sandip Bankewar wrote:





------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe&lt;/pre&gt;</description>
    <dc:creator>Sandip Bankewar</dc:creator>
    <dc:date>2012-05-25T05:46:22</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36717">
    <title>Re: Snort and real-time alerting</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36717</link>
    <description>&lt;pre&gt;I understand what you are saying, and in theory it can certainly
provide some insight into attacks against what it is that "you" are
"trying" to "protect".. that said.. why are you even allowing mysql
from the outside in your example, seems like a bad practice in the
first place, this is the kind of thing that generic firewalls and
logging thereof are for, no?  That type of thing notwithstanding, if
you can turn on more rules and look at traffic that may be "real"
attack traffic against things that "you" "don't" have, and still be
able to manage your alert volume, then more power to ya, I say if it
works for you then stick with it.. certainly not my methodology though
and I don't see how it's scalable in an environment with significant
traffic volume and a potentially large attack surface.

JJC

On Thu, May 24, 2012 at 10:09 AM, waldo kitty &amp;lt;wkitty42&amp;lt; at &amp;gt;windstream.net&amp;gt; wrote:

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event wil&lt;/pre&gt;</description>
    <dc:creator>JJC</dc:creator>
    <dc:date>2012-05-24T19:40:17</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36716">
    <title>Re: Snort and real-time alerting</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36716</link>
    <description>&lt;pre&gt;
agreed...


that's a bad thing? if "you" attempt to see if "i" have mysql accessible from 
the outside by trying to throw an attack at it, "i" want you blocked... 
period... even if "i" never use mysql ever... the same statement applies if 
"you" throw wordpress hacks at my network and "i'm" not running any dynamic 
pages at all... or VOIP SIP scans... or SOLARIS telnet buffer overruns... etc...

"you" tried something dirty... that's all the proof needed in my book... 
watching only for traffic that might affect the stuff you do run is allowing a 
whole mash of other unnecessary traffic into your network that is attempting to 
attack stuff you don't run... why allow any bad traffic at all? would you like 
someone to test your house/apartment front door all the time every day to see if 
it is unlocked or would you do something about it? ;)



------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's sec&lt;/pre&gt;</description>
    <dc:creator>waldo kitty</dc:creator>
    <dc:date>2012-05-24T16:09:20</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36715">
    <title>Re: Testing snort</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36715</link>
    <description>&lt;pre&gt;Snort can read pcap files directly.

snort -c /etc/snort/conf -r &amp;lt;file.pcap&amp;gt;


Joel

On May 24, 2012, at 6:04 AM, Sandip Bankewar wrote:



------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Joel Esler</dc:creator>
    <dc:date>2012-05-24T12:33:08</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36714">
    <title>Re: Testing snort</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36714</link>
    <description>&lt;pre&gt;Sounds complicated :)

Couldn't he just feed the pcap directly to snort:

snort -r &amp;lt;file.pcap&amp;gt; ?

On Thu, May 24, 2012 at 9:19 AM, Nick Moore &amp;lt;nmoore&amp;lt; at &amp;gt;sourcefire.com&amp;gt; wrote:



&lt;/pre&gt;</description>
    <dc:creator>Paul Halliday</dc:creator>
    <dc:date>2012-05-24T12:33:37</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36713">
    <title>Re: Testing snort</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36713</link>
    <description>&lt;pre&gt;Sandip,

I have only used it in Linux and Mac OSX. I have to confess that I haven't
used Windows as my primary workstation for over six years and am not
familiar with current tools for it. The website mentions Cygwin, which if I
remember correctly creates a Linux-like environment for Windows. So you're
pretty much back to square one.

If there are other users on the list who are more knowledgable regarding
Windows and available tcpreplay-like utilities, please chime in.

Regarding installation instructions, installing from source is pretty much
the same as any package:

   - tar -zxvf tcpreplay-3.x.x.tar.gz
   - cd tcpreplay-3.x.x
   - ./configure &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install

If you run Debian or Ubuntu, you can use apt-get. Most RPM based distro's
should have tcpreplay. (blatantly plagiarizing from the website).

To quote Marty Roesch "Learn to use Linux. Like eating your broccoli, it's
good for you." A really good start would be to download a Snort set up doc
for Ubuntu or CentOS and follow it through. David G&lt;/pre&gt;</description>
    <dc:creator>Nick Moore</dc:creator>
    <dc:date>2012-05-24T12:19:56</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36712">
    <title>Testing snort</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36712</link>
    <description>&lt;pre&gt;Hi All,

I want to test snort using large packets.
I started wireshark and started to capture traffic. I am planning to save .pcap file and load it into a system running snort.
My question is how can I load .pcap or wireshark file to that system?
Is there any tool?

Is there any other method to test it?


Regards,
Sandip Bankewar

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-&lt;/pre&gt;</description>
    <dc:creator>Sandip Bankewar</dc:creator>
    <dc:date>2012-05-24T10:04:08</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36711">
    <title>Daemonlogger native package now in OpenWRT trunk!</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36711</link>
    <description>&lt;pre&gt;My patch for building Daemonlogger as a native OpenWRT package has been 
accepted into the mainline distribution and committed to trunk. 
Pre-built binary packages are now available for all supported 
architectures in the nightly snapshots tree.

Unfortunately these packages only work on the latest trunk firmware 
builds at the moment, and the 3.2 kernel along with the extra software 
included in these builds does not leave enough free JFFS space or usable 
RAM to run daemonlogger effectively. I'm trying to convince the 
developers to include this in the next stable release of Backfire 
(10.03.2) based on the 2.6 kernel, but no luck yet.

For the time being you can still grab my binary package from my GitHub 
repository. This one *does* install and run cleanly on the current 
stable version of Backfire (10.03.1).

   - Announcement: http://goo.gl/Wy5G8
   - Downloads: https://github.com/vineyard/WRT-SPAN

Cheers,
Robert Vineyard

------------------------------------------------------------------------------
&lt;/pre&gt;</description>
    <dc:creator>Robert Vineyard</dc:creator>
    <dc:date>2012-05-23T23:14:17</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36710">
    <title>Re: Snort and real-time alerting</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36710</link>
    <description>&lt;pre&gt;Tune that system.. I can fairly safely assume that if you have 20,000
rules enabled, you are looking for attacks against stuff that you
don't have.

JJC

On Wed, May 23, 2012 at 8:51 AM, Jeronimo L. Cabral
&amp;lt;jelocabral&amp;lt; at &amp;gt;gmail.com&amp;gt; wrote:

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>JJC</dc:creator>
    <dc:date>2012-05-23T19:45:19</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36709">
    <title>Re: Snort and real-time alerting</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36709</link>
    <description>&lt;pre&gt;Sguil can do auto email on some events only.. it can email by
category, priority or just sid..

On Wed, May 23, 2012 at 2:57 PM, Lay, James &amp;lt;james.lay&amp;lt; at &amp;gt;wincofoods.com&amp;gt; wrote:

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Jeremy Hoel</dc:creator>
    <dc:date>2012-05-23T15:03:31</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36708">
    <title>Re: Snort and real-time alerting</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36708</link>
    <description>&lt;pre&gt;
Have the watching app look for specific things...perhaps only certain
classifications ("A Network Trojan was Detected") or something of the
like.

James

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Lay, James</dc:creator>
    <dc:date>2012-05-23T14:57:16</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36707">
    <title>Re: Snort and real-time alerting</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36707</link>
    <description>&lt;pre&gt;Something else: suppose I use logsurfer/swatch/logwatch to alert in
real time the Snorts events. Actually I have near 5 events per minute.

What is the criteria to take just a few number of critical events of
Snort ??? Because I have 20.000 signatures...

On Wed, May 23, 2012 at 11:40 AM, Jeronimo L. Cabral
&amp;lt;jelocabral&amp;lt; at &amp;gt;gmail.com&amp;gt; wrote:

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?lis&lt;/pre&gt;</description>
    <dc:creator>Jeronimo L. Cabral</dc:creator>
    <dc:date>2012-05-23T14:51:50</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36706">
    <title>Re: Snort and real-time alerting</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36706</link>
    <description>&lt;pre&gt;
Hehe...whatever works :)

James

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Lay, James</dc:creator>
    <dc:date>2012-05-23T14:47:12</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36705">
    <title>Re: Snort and real-time alerting</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36705</link>
    <description>&lt;pre&gt;What about Swatch ??? Is it more appropriate ???

On Wed, May 23, 2012 at 11:13 AM, Lay, James &amp;lt;james.lay&amp;lt; at &amp;gt;wincofoods.com&amp;gt; wrote:

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Jeronimo L. Cabral</dc:creator>
    <dc:date>2012-05-23T14:40:30</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36704">
    <title>Re: Snort and real-time alerting</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36704</link>
    <description>&lt;pre&gt;
Log to fast alert then use wots/logsurfer/logwatch to tail/watch the
file and email out.  Assuming linux/BSD/OSX.

James

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Lay, James</dc:creator>
    <dc:date>2012-05-23T14:13:57</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36703">
    <title>Snort and real-time alerting</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36703</link>
    <description>&lt;pre&gt;Dear, I have a Snort 2.9 with Base running OK, but I need a real time
alerting mechanism via email if possible.

How can I do that ??? Any extra module to use in that way ???

Special thanks

JeLo

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Jeronimo L. Cabral</dc:creator>
    <dc:date>2012-05-23T14:10:05</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36702">
    <title>Re: New snort install question</title>
    <link>http://permalink.gmane.org/gmane.comp.security.ids.snort.general/36702</link>
    <description>&lt;pre&gt;Good plan. Power supplies always go; it is not a question of if, it is a 
question of when..
As a back of the envelope calculation. If you use PF_RING (to run 3-4 
snort processes in parallel on you 3-4 hyperthreads), roughly, you will 
be able to monitor 100-300 Mbps with ~6000 rules.
See www.*snort*.org/assets/186/*PF_RING*_*Snort*_Inline_Instructions.pdf
You are smart.. Internal monitoring can be challenging because of the 
rule tuning required; but it is also very important in my opinion. Today 
smart phones/ laptops traverse firewalls every day; so perimeter 
defenses are getting obsolete.. You are going to need a good event 
management system..


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.co&lt;/pre&gt;</description>
    <dc:creator>livio Ricciulli</dc:creator>
    <dc:date>2012-05-22T01:27:29</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.comp.security.ids.snort.general">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.comp.security.ids.snort.general</link>
  </textinput>
</rdf:RDF>

