Aanval has many options to log, add notes to event data, and report.
1. Collect information about the event (attackers, signatures, internal systems, etc)
Aanval imports and logs all event data provided by Snort. On the dashboard or Live Event Monitor, clicking Event Details on a specific event will show you all the data provided by Snort.
2. Record our thoughts (The ticket component)
Aanval provides a tagging system. While viewing those same Event Details, you can add individual tags. Under My Options > Tag Management, you can create custom tags, aside from those default tags provided.
3. attach various queries to the case
Using the My Reports option you can create custom reports to be scheduled and emailed based on event criteria.
Once results are returned, you can then click the option to "Generate report from results."
4. email the case
When viewing any report, you can email it in PDF or text format from the My Reports menu. The report will be sent to the email address of the user currently logged in.