[Oisf-users] replacing snort with suricata under sguil 0.7.0

carlopmart carlopmart at gmail.com
Fri Mar 25 23:07:44 UTC 2011


Hi all,

  I am trying to replace one snort sensor with suricata. This sensor is 
configured against a sguil 0.7.0 server.

  I am seeing some options configured on some sguil agents configuration 
files that differs for suricata. For example in snort_agent.conf file in:

set SNORT_PERF_FILE "${LOG_DIR}/${HOSTNAME}/snort.stats"

  Obviously, suricata parse in different manner stats file. But, is it 
possible to integrate suricata under sguil 0.7.0?? What options do I 
need to disable or enable to do this??

Many thanks.

-- 
CL Martinez
carlopmart {at} gmail {d0t} com



More information about the Oisf-users mailing list