[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Real Time monitoring/alerting utility..



On Thu, Aug 26, 2004 at 08:14:50AM +1000, Michael Bellears wrote:

> No - He wants to be notified immediately if an FTP or SSH connection is
> established.

Using snort and tailing the logfile, it doesn't get much more real
time than that.  Just modify the config files to treat all accesses as
alerts.  Use acidlab with it and you have a history of every access,
ever.

-- 
  _   _   _   _   _   _   _   _   _   _   _   _   _  
 / \ / \ / \ / \ / \ / \ / \ / \ / \ / \ / \ / \ / \ 
( t | i | m | @ | i | t | . | k | p | t | . | c | c )
 \_/ \_/ \_/ \_/ \_/ \_/ \_/ \_/ \_/ \_/ \_/ \_/ \_/ 
GPG key fingerprint = 1DEE CD9B 4808 F608 FBBF  DC21 2807 D7D3 09CA 85BF



Reply to: