Snort Notify

Post your EasyIDS feedback & suggestions here

Snort Notify

Postby stupots » Fri Feb 26, 2010 6:08 am

How about running two separate instances of SnortNotify so that for people in a large organisation, you can send different levels of alert to different groups of people? Eg, we operate 24/7 but the staff are less capable than the 9-5ers (such as me). I'd like them to receive only severity 1 alerts, but at the same time, I'd like to personally receive severity 1 and 2 alerts, so that I can see the information alerts that would precede an outright attack...

Also, I'd like to be able to send a more detailed email that contains things such as hyperlinks to documentation on our internal Wiki. I've tried embedding html within the message, but 1) it repeats on every line and 2) the html gets rendered in plain text. Unfortunately, this will probably require changes to Snort Notify to be possible :(

Regards,
Stuart
stupots
 
Posts: 13
Joined: Tue Feb 23, 2010 9:43 am
Location: Somewhere in the UK

Re: Snort Notify

Postby oakleeman » Thu Mar 04, 2010 2:34 am

Good ideas. I wonder if the SnortNotify developers would be able to help any with this....or maybe another user can take a look at the perl code and submit some modifications.
Making Open Source Easier
oakleeman
 
Posts: 156
Joined: Tue Sep 29, 2009 12:27 am


Return to Suggestions

Who is online

Users browsing this forum: No registered users and 1 guest

cron