Q

Can Snort read multi-platform syslogs?

Most security pros are aware of Snort's network intrusion detection capabilities, but can this freeware tool read and monitor multi-platform syslogs? SearchSecurity's network security expert Mike Chapple tackles this question in this Ask the Expert Q&A.

Is there a way to read multi-platform syslogs through Snort?
As you probably know, Snort is primarily a network intrusion detection system, designed to directly monitor a network for activity that matches certain patterns (the Snort ruleset). Unfortunately, it's really not a good tool for monitoring syslog traffic, because it's simply not designed for the task. However, there are a number of tools that can help analyze log data. If you're looking for a tool that helps perform offline analysis on the desktop, Sawmill is one of my favorites. Its major strength lies in its ability to tackle just about any log format you throw at it. If you want a system that provides real-time alerting, based upon syslog data, consider the open source Swatch (syslog watch) project. It's the "Snort of syslogs."

For More Information

  • Learn how to install, and configure Snort in this technical guide.
  • Visit our resource center for news, tips and expert advice on how to install and use open source security tools in your organization.
  • This was first published in June 2006

    Dig deeper on Network Intrusion Detection (IDS)

    Pro+

    Features

    Enjoy the benefits of Pro+ membership, learn more and join.

    Have a question for an expert?

    Please add a title for your question

    Get answers from a TechTarget expert on whatever's puzzling you.

    You will be able to add details on the next page.

    0 comments

    Oldest 

    Forgot Password?

    No problem! Submit your e-mail address below. We'll send you an email containing your password.

    Your password has been sent to:

    -ADS BY GOOGLE

    SearchCloudSecurity

    SearchNetworking

    SearchCIO

    SearchConsumerization

    SearchEnterpriseDesktop

    SearchCloudComputing

    ComputerWeekly

    Close