<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-4482521283458453577.post807464665455637577..comments</id><updated>2011-09-13T07:40:48.147-07:00</updated><category term='SCCM'/><category term='AES'/><category term='the force'/><category term='jedi'/><category term='risk management'/><category term='passwords'/><category term='nbnsspoof'/><category term='youngling'/><category term='diversion'/><category term='updates'/><category term='externality'/><category term='bullshit'/><category term='help'/><category term='Outlook Web Access'/><category term='OS X'/><category term='gnome'/><category term='quality assurance'/><category term='encryption'/><category term='backtrack'/><category term='risk modeling'/><category term='auditing'/><category term='nbnspoof'/><category term='sith'/><category term='metrics'/><category term='python'/><category term='rails'/><category term='contact'/><category term='pointsec'/><category term='DMCA'/><category term='script'/><category term='dark side'/><category term='data loss prevention'/><category term='lockpicking'/><category term='fde'/><category term='NPV'/><category term='Application Layer Firewall'/><category term='New School'/><category term='lightsaber'/><category term='Form 0'/><category term='snort'/><category term='black fist'/><category term='monte carlo'/><category term='linux'/><category term='Book Review'/><category term='change management'/><category term='incident response'/><category term='openbsd'/><category term='PCI'/><category term='VMWare'/><category term='form III'/><category term='relayd'/><category term='security'/><category term='information'/><category term='novell'/><category term='awkward'/><category term='padawan'/><category term='policies'/><category term='video tutorial'/><category term='jar jar binks'/><category term='forensics'/><category term='TrustedSource'/><category term='mind trick'/><category term='form II'/><category term='phishing'/><category term='copyright'/><category term='economics'/><category term='antivirus'/><category term='blogger'/><category term='unix'/><category term='mac'/><category term='R72'/><category term='event logs'/><category term='Deadly Whisper'/><category term='Sidewinder'/><category term='Ubuntu'/><category term='project management'/><category term='statistics'/><category term='google'/><title type='text'>Comments on Black Fist Security: Time-based alerts for snort</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.blackfistsecurity.com/feeds/807464665455637577/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/807464665455637577/comments/default'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2009/12/time-based-alerts-for-snort.html'/><author><name>kevin thompson</name><uri>https://profiles.google.com/107682921975811187169</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-njbZ3e90-4I/AAAAAAAAAAI/AAAAAAAAAP8/tYdzjKjLpUg/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4482521283458453577.post-4144628100734655436</id><published>2011-09-13T04:34:58.561-07:00</published><updated>2011-09-13T04:34:58.561-07:00</updated><title type='text'>Great post!  

Have you looked at OSSEC?  It can r...</title><content type='html'>Great post!  &lt;br /&gt;&lt;br /&gt;Have you looked at OSSEC?  It can read Snort logs natively.  You can then write OSSEC rules that look for specific Snort alerts in a specific timeframe.  If the OSSEC rule fires, then OSSEC can generate an email or even Active Response (block the offending IP at the firewall).&lt;br /&gt;&lt;br /&gt;Hope that helps!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/807464665455637577/comments/default/4144628100734655436'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/807464665455637577/comments/default/4144628100734655436'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2009/12/time-based-alerts-for-snort.html?showComment=1315913698561#c4144628100734655436' title=''/><author><name>Doug Burks</name><uri>http://www.blogger.com/profile/09074300658047188367</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/_Prlv_CKbUdQ/S8hAOGUlugI/AAAAAAAAABE/Co1g2wW6WLI/S220/Doug_mug.JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.blackfistsecurity.com/2009/12/time-based-alerts-for-snort.html' ref='tag:blogger.com,1999:blog-4482521283458453577.post-807464665455637577' source='http://www.blogger.com/feeds/4482521283458453577/posts/default/807464665455637577' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1466773305'/></entry></feed>
