mirror of
https://github.com/vimagick/dockerfiles.git
synced 2024-11-28 09:08:50 +02:00
update snort alert
This commit is contained in:
parent
7414dac1f3
commit
26b8d99a3b
@ -9,7 +9,7 @@ traffic analysis and packet logging.
|
||||
```yaml
|
||||
snort:
|
||||
image: vimagick/snort
|
||||
command: -q -c /etc/snort/snort.conf -A console -i ens3
|
||||
command: -q -c /etc/snort/snort.conf -A fast -y -i eth0
|
||||
volumes:
|
||||
- ./data/snort.conf:/etc/snort/snort.conf
|
||||
- ./data/rules:/etc/snort/rules
|
||||
@ -30,9 +30,9 @@ alert icmp any any -> any any (msg:"ICMP Echo Reply"; itype:0; sid:10001;)
|
||||
```bash
|
||||
$ docker-compose up -d
|
||||
|
||||
$ docker-compose logs --tail 10 -f
|
||||
snort_1 | 08/26-06:47:35.460754 [**] [1:10000:0] ICMP Echo Request [**] [Priority: 0] {ICMP} x.x.x.x -> y.y.y.y
|
||||
snort_1 | 08/26-06:47:35.460835 [**] [1:10001:0] ICMP Echo Reply [**] [Priority: 0] {ICMP} y.y.y.y -> x.x.x.x
|
||||
$ tail -f data/log/alert
|
||||
snort_1 | 08/26/18-06:47:35.460754 [**] [1:10000:0] ICMP Echo Request [**] [Priority: 0] {ICMP} x.x.x.x -> y.y.y.y
|
||||
snort_1 | 08/26/18-06:47:35.460835 [**] [1:10001:0] ICMP Echo Reply [**] [Priority: 0] {ICMP} y.y.y.y -> x.x.x.x
|
||||
|
||||
$ tcpdump -n -r data/log/snort.log.xxx
|
||||
06:47:35.460754 IP x.x.x.x > y.y.y.y: ICMP echo request, id 17767, seq 933, length 12
|
||||
|
@ -1,6 +1,6 @@
|
||||
snort:
|
||||
image: vimagick/snort
|
||||
command: -q -c /etc/snort/snort.conf -A console -k none -i ens3
|
||||
command: -q -c /etc/snort/snort.conf -A fast -y -i eth0
|
||||
volumes:
|
||||
- ./data/snort.conf:/etc/snort/snort.conf
|
||||
- ./data/rules:/etc/snort/rules
|
||||
|
Loading…
Reference in New Issue
Block a user