_ , Snort (, eth0 eth1).
, HOME_NET EXTERNAL_NET. any. . , any.
. , WEB, MAIL, DNS, SQL TELNET. .
, . , , . AIM, AOL Instant Messenger. , Chat.
Snort. Snort. , - , , , . . Snort , . , , Snort .
. , , . . , , Snort, , .
. , Snort. , . , : Syslog, Database Unified, , .
:
Output _:
_ alert_syslog, database alert_unified .
.
Syslog
UNIX/Linux :
|
|
Output alert_syslog: LOG_AUTH LOG_ALERT
Windows- :
Output alert_syslog: LOG_AUTH LOG_ALERT
output alert_syslog: host=_, LOG_AUTH LOG_ALERT
output alert_syslog: host=_:, LOG_AUTH LOG_ALERT
_ , , IP- Syslog.
Database
:
output database: log, __, user=_
password= dbname=_ host=_
__ Snort (MySQL, postgresql, unixodbc mssql), _ , . dbname . , __ IP- . Snort . , , Snort .
Unified
. filename limit, :