[collectd] Snort plugin

Jeffrey B. Green jeff at kikisoso.org
Thu Dec 9 15:30:31 CET 2010


Hi,

In the interim until a full binary plugin for snort is developed, I've 
put together this perl plugin that works off of the perfmonitor stats 
file. I'm not sure if it needs to be a permanent addition since it looks 
as though a binary plugin is being developed (although adding it is okay 
if the collectd development wants to add it in...rename it as you wish). 
If anyone wants to use it, then here it is (attached). It needs its 
included auxiliary types.db file to be known via the collectd.conf file. 
I put it in /e/collectd but possibly alongside the plugin is possibly 
better. I'll probably/hopefully add a config function when our 
production machines move to debian squeeze. Also the types.db and the 
pattern expression need a bit of polishing since I haven't had enough 
time to investigate all of the different values printed out by perfmonitor.

-jeff
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Snort_plugin.tgz
Type: application/x-gtar
Size: 2709 bytes
Desc: not available
URL: <http://mailman.verplant.org/pipermail/collectd/attachments/20101209/232253a1/attachment.tgz>


More information about the collectd mailing list