When trying to change the colour of an IP (Source or Destination) you get the following pop up error message in Squert:
INSERT,UPDATE command denied to user 'readonly'@'localhost' for table 'object_mappings'
To reproduce:
- select an event
- click on either the Source or Destination IP address
- Select a colour and click update.
This might be a limitation as to how squert runs in SO.
One thing which I liked in Snorby was the ability to map IP addresses with hostnames, so you could easily recognise certains local host when looking at alerts/events.
As I don't think you can do that in Squert, I was hoping to be able to colour code certain IP.
Bugs.