Discussion:
Snort N Zenoss
Mike Johnson
2013-02-04 17:03:21 UTC
Permalink
Mike Johnson [http://community.zenoss.org/people/Learner] created the discussion

"Re: Snort N Zenoss"

To view the discussion, visit: http://community.zenoss.org/message/71373#71373

--------------------------------------------------------------
Hello,



I am a new user of zenoss and trying to develop an infrastructure on my own. I am trying to send logs (that contains cpu, timestamp, status, etc.) from external software/device (such as snort, snorby) to zenoss. I spent hours on researching this but unable to figure out.


1) How to take those log files from snort or snorby  into my zenoss 4.2.3? How do I set up a listening port for zenoss to receive those data points? How can I get those log files in my zenoss and display it somewhere in my portlet? How do I map those events?


Please provide me detailed help. I feel like you have done it before.


Again, I am learning and I appreciate any DETAIL help from this community.
--------------------------------------------------------------

Reply to this message by replying to this email -or- go to the discussion on Zenoss Community
[http://community.zenoss.org/message/71373#71373]

Start a new discussion in zenoss-users by email
[discussions-community-forums-zenoss--***@community.zenoss.org] -or- at Zenoss Community
[http://community.zenoss.org/choose-container!input.jspa?contentType=1&containerType=14&container=2003]
nilie
2013-02-04 20:33:22 UTC
Permalink
nilie [http://community.zenoss.org/people/nilie] created the discussion

"Re: Snort N Zenoss"

To view the discussion, visit: http://community.zenoss.org/message/71376#71376

--------------------------------------------------------------
What you're experiencing is that Zenoss by itself is unable to properly parse the syslog messages sent by Snort. Can you paste here one of those syslog messages sent by Snort ?
--------------------------------------------------------------

Reply to this message by replying to this email -or- go to the discussion on Zenoss Community
[http://community.zenoss.org/message/71376#71376]

Start a new discussion in zenoss-users by email
[discussions-community-forums-zenoss--***@community.zenoss.org] -or- at Zenoss Community
[http://community.zenoss.org/choose-container!input.jspa?contentType=1&containerType=14&container=2003]
nilie
2013-02-04 20:40:57 UTC
Permalink
nilie [http://community.zenoss.org/people/nilie] created the discussion

"Re: Snort N Zenoss"

To view the discussion, visit: http://community.zenoss.org/message/71377#71377

--------------------------------------------------------------
Provide us with more details. What those log files are and what exactly do you want to display ?
--------------------------------------------------------------

Reply to this message by replying to this email -or- go to the discussion on Zenoss Community
[http://community.zenoss.org/message/71377#71377]

Start a new discussion in zenoss-users by email
[discussions-community-forums-zenoss--***@community.zenoss.org] -or- at Zenoss Community
[http://community.zenoss.org/choose-container!input.jspa?contentType=1&containerType=14&container=2003]
Mike Johnson
2013-02-04 23:13:21 UTC
Permalink
Mike Johnson [http://community.zenoss.org/people/Learner] created the discussion

"Re: Snort N Zenoss"

To view the discussion, visit: http://community.zenoss.org/message/71362#71362

--------------------------------------------------------------
My first challenge is how would I receive Snort log files (any formats as in ASCII, txt( into Zenoss? I want help in getting started?

Second, once I get those files how can I display those in one of the portlet in the zenoss, in tabular format (if possible?

I will post log files tonight.
--------------------------------------------------------------

Reply to this message by replying to this email -or- go to the discussion on Zenoss Community
[http://community.zenoss.org/message/71362#71362]

Start a new discussion in zenoss-users by email
[discussions-community-forums-zenoss--***@community.zenoss.org] -or- at Zenoss Community
[http://community.zenoss.org/choose-container!input.jspa?contentType=1&containerType=14&container=2003]
Loading...