[collectd] Snort plugin
Jeffrey B. Green
jeff at kikisoso.org
Thu Dec 9 15:30:31 CET 2010
Hi,
In the interim until a full binary plugin for snort is developed, I've
put together this perl plugin that works off of the perfmonitor stats
file. I'm not sure if it needs to be a permanent addition since it looks
as though a binary plugin is being developed (although adding it is okay
if the collectd development wants to add it in...rename it as you wish).
If anyone wants to use it, then here it is (attached). It needs its
included auxiliary types.db file to be known via the collectd.conf file.
I put it in /e/collectd but possibly alongside the plugin is possibly
better. I'll probably/hopefully add a config function when our
production machines move to debian squeeze. Also the types.db and the
pattern expression need a bit of polishing since I haven't had enough
time to investigate all of the different values printed out by perfmonitor.
-jeff
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Snort_plugin.tgz
Type: application/x-gtar
Size: 2709 bytes
Desc: not available
URL: <http://mailman.verplant.org/pipermail/collectd/attachments/20101209/232253a1/attachment.tgz>
More information about the collectd
mailing list