LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-30-2019, 06:30 AM   #1
winxlinx@gmail.com
LQ Newbie
 
Registered: Jun 2014
Posts: 7

Rep: Reputation: Disabled
In the ubuntu or any other Linux, can we monitor the syslog with snort ?


Hi All,

I know that snort can monitor the interface or span port, But any idea snort can monitor the syslog server logs ?

Like for example if install the snort on the syslog server ? is possible?
 
Old 08-30-2019, 06:40 AM   #2
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS, Manjaro
Posts: 5,765

Rep: Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764
SNORT is an excellent Network Intrusion Detection System (NIDS) that works by packet analysis rules, it is not a log monitor system. There are some excellent log monitors, but that is not the function of an NIDS. I suspect you will want to oobtain, learn, and configure a log monitor to summarize and report on your log files, possibly to include your snort logs.
 
Old 08-30-2019, 06:49 AM   #3
winxlinx@gmail.com
LQ Newbie
 
Registered: Jun 2014
Posts: 7

Original Poster
Rep: Reputation: Disabled
Thanks i got your point, I was thinking if snort can do the log monitor as well, Not sure if this possible when i checked your reply.

But snort cannot be installed all the machines which i need to monitor right or not all the situations i can span port to snort machines right ?

For example if i wanted to monitor the windows iis web server with snort? How this is possible ?
 
Old 08-31-2019, 07:17 AM   #4
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS, Manjaro
Posts: 5,765

Rep: Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764
Quote:
Originally Posted by winxlinx@gmail.com View Post
Thanks i got your point, I was thinking if snort can do the log monitor as well, Not sure if this possible when i checked your reply.

But snort cannot be installed all the machines which i need to monitor right or not all the situations i can span port to snort machines right ?

For example if i wanted to monitor the windows iis web server with snort? How this is possible ?
Snort is a Network Intrusion Detection System. That SHOULD imply that as long as it will run on your network it provides some detection for the entire network. Obviously there are ways to better deploy it, but there is nothing about Windows (Since WinNT 3.5 anyway) that makes it NOT be a part of your network.

If you mean you want to INSTALL it on Windows, that can work as well. Check this page: https://www.snort.org/#get-started and you will find packages of SNORT for Fedora, CentOS (and RHEL), FreeBSD, Windows, and as source. The source based install can be compiled onto any platform where you can compile the prerequisites and that source.

In addition, a 10 second search using DuckDuckGo (Google or BINK might have worked as well) brings one to this link https://blog.rapid7.com/2017/01/11/h...-ubuntu-linux/ which would seem to apply.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Why is syslog-ng not recording any log events in /var/log/syslog.log ToffeeYogurtPots Linux - Software 3 05-31-2018 02:15 PM
[SOLVED] Snort installed on ubuntu not sending alerts to syslog haim Linux - General 3 09-22-2015 06:32 AM
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 02:59 PM
snort failed: snort: symbol lookup error: undefined symbol: usmAES192PrivProtocol Emmanuel_uk Linux - Security 1 07-10-2005 10:29 AM
snort snort.conf help crealkiller175 Linux - Software 1 03-08-2003 05:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration