mirror of
https://github.com/vimagick/dockerfiles.git
synced 2025-12-21 13:23:02 +01:00
update snort alert
This commit is contained in:
@@ -9,7 +9,7 @@ traffic analysis and packet logging.
|
|||||||
```yaml
|
```yaml
|
||||||
snort:
|
snort:
|
||||||
image: vimagick/snort
|
image: vimagick/snort
|
||||||
command: -q -c /etc/snort/snort.conf -A console -i ens3
|
command: -q -c /etc/snort/snort.conf -A fast -y -i eth0
|
||||||
volumes:
|
volumes:
|
||||||
- ./data/snort.conf:/etc/snort/snort.conf
|
- ./data/snort.conf:/etc/snort/snort.conf
|
||||||
- ./data/rules:/etc/snort/rules
|
- ./data/rules:/etc/snort/rules
|
||||||
@@ -30,9 +30,9 @@ alert icmp any any -> any any (msg:"ICMP Echo Reply"; itype:0; sid:10001;)
|
|||||||
```bash
|
```bash
|
||||||
$ docker-compose up -d
|
$ docker-compose up -d
|
||||||
|
|
||||||
$ docker-compose logs --tail 10 -f
|
$ tail -f data/log/alert
|
||||||
snort_1 | 08/26-06:47:35.460754 [**] [1:10000:0] ICMP Echo Request [**] [Priority: 0] {ICMP} x.x.x.x -> y.y.y.y
|
snort_1 | 08/26/18-06:47:35.460754 [**] [1:10000:0] ICMP Echo Request [**] [Priority: 0] {ICMP} x.x.x.x -> y.y.y.y
|
||||||
snort_1 | 08/26-06:47:35.460835 [**] [1:10001:0] ICMP Echo Reply [**] [Priority: 0] {ICMP} y.y.y.y -> x.x.x.x
|
snort_1 | 08/26/18-06:47:35.460835 [**] [1:10001:0] ICMP Echo Reply [**] [Priority: 0] {ICMP} y.y.y.y -> x.x.x.x
|
||||||
|
|
||||||
$ tcpdump -n -r data/log/snort.log.xxx
|
$ tcpdump -n -r data/log/snort.log.xxx
|
||||||
06:47:35.460754 IP x.x.x.x > y.y.y.y: ICMP echo request, id 17767, seq 933, length 12
|
06:47:35.460754 IP x.x.x.x > y.y.y.y: ICMP echo request, id 17767, seq 933, length 12
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
snort:
|
snort:
|
||||||
image: vimagick/snort
|
image: vimagick/snort
|
||||||
command: -q -c /etc/snort/snort.conf -A console -k none -i ens3
|
command: -q -c /etc/snort/snort.conf -A fast -y -i eth0
|
||||||
volumes:
|
volumes:
|
||||||
- ./data/snort.conf:/etc/snort/snort.conf
|
- ./data/snort.conf:/etc/snort/snort.conf
|
||||||
- ./data/rules:/etc/snort/rules
|
- ./data/rules:/etc/snort/rules
|
||||||
|
|||||||
Reference in New Issue
Block a user