You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to sagan-users
I am interested in using the active response feature of snortsam in sagan.yaml but it seems this option is a bit dated. Is there another alternative, i.e. fwsnort or snort2iptables that may be used or anything that could help to reject or drop offending IP addresses from within Sagan?
Champ Clark III
unread,
Apr 16, 2020, 6:45:32 PM4/16/20
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to sagan-users
"Snortsam" support has been depreciated. What you'll likely want to do is run Meer with "external" output support. This allows Meer to call an external routine. When the external routine is called, the JSON/EVE of the event is passed to the external program. Your external program can be written in any language you desire.