Groups
Groups
Sign in
Groups
Groups
Aanval - Snort & Syslog SIEM (Correlation and Threat Management)
Conversations
About
Send feedback
Help
Aanval - Snort & Syslog SIEM (Correlation and Threat Management)
1–30 of 1514
Mark all as read
Report group
0 selected
alesnav
5/4/17
Send Aanval audit data (Console events) to a Syslog destination
Hello there! I'd want to send all events logged by Aanval to a SIEM, just for audit topics. When
unread,
Send Aanval audit data (Console events) to a Syslog destination
Hello there! I'd want to send all events logged by Aanval to a SIEM, just for audit topics. When
5/4/17
Travis Barlow
,
SuperheroSmith
4
9/15/14
Aanval Ossec Syslog feed
The filter below should grab the source IP: ((?<=Source Network Address: )[0-9.]+) You can modify
unread,
Aanval Ossec Syslog feed
The filter below should grab the source IP: ((?<=Source Network Address: )[0-9.]+) You can modify
9/15/14
Digipark.com
4/6/14
[Support #RLT-357-91019]: [aanval] Digest for aanval@googlegroups.com - 2 updates in 1 topic
aan...@googlegroups.com, Thank you for contacting us. This is an automated response confirming the
unread,
[Support #RLT-357-91019]: [aanval] Digest for aanval@googlegroups.com - 2 updates in 1 topic
aan...@googlegroups.com, Thank you for contacting us. This is an automated response confirming the
4/6/14
Justin Beeler
,
SuperheroSmith
2
4/6/14
Can't get Snort name to work on snort module settings page! Database name failure
If the connection to the database is successful, all should be fine. You can confirm this by
unread,
Can't get Snort name to work on snort module settings page! Database name failure
If the connection to the database is successful, all should be fine. You can confirm this by
4/6/14
Digipark.com
2/25/14
[Support #NET-758-55870]: [aanval] Digest for aanval@googlegroups.com - 2 Messages in 1 Topic
aan...@googlegroups.com, Thank you for contacting us. This is an automated response confirming the
unread,
[Support #NET-758-55870]: [aanval] Digest for aanval@googlegroups.com - 2 Messages in 1 Topic
aan...@googlegroups.com, Thank you for contacting us. This is an automated response confirming the
2/25/14
didscodan
,
SuperheroSmith
2
2/24/14
Managing incidents - case management / ticket details
Aanval has many options to log, add notes to event data, and report. 1. Collect information about the
unread,
Managing incidents - case management / ticket details
Aanval has many options to log, add notes to event data, and report. 1. Collect information about the
2/24/14
Digipark.com
1/13/14
[Support #DTT-339-19642]: [aanval] Digest for aanval@googlegroups.com - 5 Messages in 1 Topic
aan...@googlegroups.com, Thank you for contacting us. This is an automated response confirming the
unread,
[Support #DTT-339-19642]: [aanval] Digest for aanval@googlegroups.com - 5 Messages in 1 Topic
aan...@googlegroups.com, Thank you for contacting us. This is an automated response confirming the
1/13/14
Sal Ila
,
SuperheroSmith
5
1/13/14
Aanval shows old Snort events only.
Thank you for those details. Looks like Aanval attempted to rotate/create a new datastore based off a
unread,
Aanval shows old Snort events only.
Thank you for those details. Looks like Aanval attempted to rotate/create a new datastore based off a
1/13/14
Doug Metz
,
SuperheroSmith
2
6/4/13
Snort Migration question
With the latest edition of Snort, you'll need Barnyard2 to parse those logs in the Unified2
unread,
Snort Migration question
With the latest edition of Snort, you'll need Barnyard2 to parse those logs in the Unified2
6/4/13
Florian Keclik
,
Eric Smith
4
3/15/13
No Snort events visible
I got it working. I have two snort sensors because of initial configuration issues with Barnyard. Of
unread,
No Snort events visible
I got it working. I have two snort sensors because of initial configuration issues with Barnyard. Of
3/15/13
John Hally
,
Florian Keclik
2
3/15/13
Re: [aanval] Digest for aanval@googlegroups.com - 3 Messages in 1 Topic
The sensor is enabled but no events are visible. It works when I use the Aanval sensor. I can see
unread,
Re: [aanval] Digest for aanval@googlegroups.com - 3 Messages in 1 Topic
The sensor is enabled but no events are visible. It works when I use the Aanval sensor. I can see
3/15/13
Twenty Twenty Vision
1/26/13
iPhone App - 20/20 Vision
iPhone App - 20/20 Vision - http://2020visioniphoneapp.weebly.com
unread,
iPhone App - 20/20 Vision
iPhone App - 20/20 Vision - http://2020visioniphoneapp.weebly.com
1/26/13
Spanish Flashcards with Pictures
1/16/13
iPhone App - Spanish Flashcards with Pictures
iPhone App - Spanish Flashcards with Pictures - http://spanishiphoneapp.weebly.com
unread,
iPhone App - Spanish Flashcards with Pictures
iPhone App - Spanish Flashcards with Pictures - http://spanishiphoneapp.weebly.com
1/16/13
Twenty Twenty Vision
9/30/12
iPhone App To Help You Regain 20/20 Vision Naturally
http://goo.gl/fHiCv - "20/20 Vision" is an iPhone app that will help you regain 20/20
unread,
iPhone App To Help You Regain 20/20 Vision Naturally
http://goo.gl/fHiCv - "20/20 Vision" is an iPhone app that will help you regain 20/20
9/30/12
iChineseFlashcards iPhone App
8/22/12
iChineseFlashcards helps you learn Chinese (Mandarin) faster by using flashcards with pictures
http://goo.gl/DquX8 - iChineseFlashcards is an iPhone app that will help you learn Chinese (Mandarin)
unread,
iChineseFlashcards helps you learn Chinese (Mandarin) faster by using flashcards with pictures
http://goo.gl/DquX8 - iChineseFlashcards is an iPhone app that will help you learn Chinese (Mandarin)
8/22/12
deeztek
, …
SuperheroSmith
14
7/6/12
Aanval with Cisco Catalyst switch
If you visit Configuration > Snort Module > Sensor Configuration, can you see any sensors
unread,
Aanval with Cisco Catalyst switch
If you visit Configuration > Snort Module > Sensor Configuration, can you see any sensors
7/6/12
hKuARek3pC hKuARek3pC
3/30/12
Aanval - Snort & Syslog SIEM (Correlation and Threat Management) - Learn Chinese (Mandarin) faster by using flashcards with pictures
Aanval - Snort & Syslog SIEM (Correlation and Threat Management) - http://www.ichineseflashcards.
unread,
Aanval - Snort & Syslog SIEM (Correlation and Threat Management) - Learn Chinese (Mandarin) faster by using flashcards with pictures
Aanval - Snort & Syslog SIEM (Correlation and Threat Management) - http://www.ichineseflashcards.
3/30/12
lightyearkev1
,
Loyal Moses
2
3/14/12
Datastores gone after upgrading to version 7?
What version did you upgrade from? This is nothing we can't help you out with, the data is
unread,
Datastores gone after upgrading to version 7?
What version did you upgrade from? This is nothing we can't help you out with, the data is
3/14/12
lightyearkev1
3/14/12
Errors after upgrading to version 7
I keep getting this in the error logs.. MySQL Query Error: Unknown column 'data' in '
unread,
Errors after upgrading to version 7
I keep getting this in the error logs.. MySQL Query Error: Unknown column 'data' in '
3/14/12
Aymen
3/7/12
Snort rule doesn't generate alerts when hosts responding simultaneously
Hi, I hope this post is not out of topic of the group... alert tcp any any -> any any (msg:"
unread,
Snort rule doesn't generate alerts when hosts responding simultaneously
Hi, I hope this post is not out of topic of the group... alert tcp any any -> any any (msg:"
3/7/12
Loyal Moses
2/15/12
Aanval v7 Released
February 2012 Announcement Newsletter Aanval v7 is now available! Tactical FLEX, Inc. is excited to
unread,
Aanval v7 Released
February 2012 Announcement Newsletter Aanval v7 is now available! Tactical FLEX, Inc. is excited to
2/15/12
JoeBoo
2
3/24/08
Snort Aanval Barnyard
I fixed my problem. I need to specify the correct sensor id in my barnyard.conf output plugin line. I
unread,
Snort Aanval Barnyard
I fixed my problem. I need to specify the correct sensor id in my barnyard.conf output plugin line. I
3/24/08
Joey
7/26/07
Running reports stops correlation
I have build 30164. Simply, everytime I run a report Aanval stops processing events. I have not found
unread,
Running reports stops correlation
I have build 30164. Simply, everytime I run a report Aanval stops processing events. I have not found
7/26/07
Administration
7/6/07
Aanval 3.1, Build 30162 Released
Aanval 3.1, Build 30162 is now available released. This is a short update on the changes made within
unread,
Aanval 3.1, Build 30162 Released
Aanval 3.1, Build 30162 is now available released. This is a short update on the changes made within
7/6/07
efanti
5/18/07
"Pre Import Configuration .. No Import Editor" syntax
Hi I'm searching to work with "Pre Import Configuration .. No Import Editor". I read :
unread,
"Pre Import Configuration .. No Import Editor" syntax
Hi I'm searching to work with "Pre Import Configuration .. No Import Editor". I read :
5/18/07
efanti
5/18/07
Data Storage with the "Rotate Now" button --> Blank Page
Hi . When I rotate my Data Storage with the "Rotate Now" button, I receive a blank page
unread,
Data Storage with the "Rotate Now" button --> Blank Page
Hi . When I rotate my Data Storage with the "Rotate Now" button, I receive a blank page
5/18/07
suntzu
,
Loyal Moses
2
5/17/07
Snort Signature Releases
Do you happen to know which signature server you are connecting to for updates? On May 17, 8:29 am,
unread,
Snort Signature Releases
Do you happen to know which signature server you are connecting to for updates? On May 17, 8:29 am,
5/17/07
photex
,
Loyal Moses
2
5/17/07
Graphs dates are completely out of order and I can't figure out why
This may have been caused by your event data being overwritten with new events if your system failed
unread,
Graphs dates are completely out of order and I can't figure out why
This may have been caused by your event data being overwritten with new events if your system failed
5/17/07
mic...@kpmcornerstone.com
5/15/07
Problems getting signature categories to display
Hi there ... I've been wrestling with this for a while, and I cannot seem to find out what I am
unread,
Problems getting signature categories to display
Hi there ... I've been wrestling with this for a while, and I cannot seem to find out what I am
5/15/07
efanti
5/8/07
Archive Manager doesn't work
Hi to all, I have a problem with the Archive Manager Module. I create a new archive...it's ok I
unread,
Archive Manager doesn't work
Hi to all, I have a problem with the Archive Manager Module. I create a new archive...it's ok I
5/8/07