|
Firewall Analyzer supports most versions of Snort.
snort.conf file (available at /etc/snort/snort.conf in linux and c:\Snort\bin\snort.conf in windows) uncomment the line that contains output information_syslog and enter the logging facility and the desired detail level (for example: output alert_syslog:host=hostname:port, LOG_AUTH LOG_ALERT)config show_year to ensure that year has been included in the alerts generated by Snort.*.* @<server_name>
at the end, where <server_name>
is the name of the machine on which Firewall Analyzer is running./etc/rc.d/init.d/syslog restart
|