Mudpit is an intelligent, modular and reliable spool processor for Snort's unified format.
Be the first to post a text review of mudpit. Rate and review a project by clicking thumbs up or thumbs down in the right column.
Version 1.5: 1) Added per spool configuration variables for SID/Gen map, reference, and class files.. 2) Improved logging system, log at appropriate priorities. 3) Improved autoconf mysql detection code and support for custome plugins supplied at configure time.
Mudpit 1.4 has been released. Improved autoconf support, converting the output plugins to libtool, and support for ACID schema version 106 are the main changes.
Version 1.4: 1) Maintainer changed from Fidelis to Farm9. 2) Tweaks made to allow compilation on FreeBSD. 3) log() renamed to logprint() to avoid gcc/C confusion with builtin log() function. 4) Completed porting code to the autoconf tools. Add checks to let -dl still work on Linux. Autoconf code to make libgnugetopt and getopt work on FreeBSD/Linux. 5) Libtoolized the output plugins. 6) Acid output plugin updated to 106 schema. If version mismatch, parent process now dies. last_cid checking added. 7) Add signal handlers to cleanly exit from SIGTERM and SIGINT.
With permission of Fidelis, Farm9 has taken over maintenance of Mudpit. Our first major changes will be: -Porting to the acid/snort db schema 106 -Clean-up autoconf and compile on *BSD
Version 1.1: 1) Command-line option '--once'. 2) Command-line option '-D' = '--daemon' now. 3) Built-in limit (3) for repeated transfer attempts for each output plugin. Spool processor will exit - and, naturally, restarted again, if this limit is reached. 4) New sevice for output plug-in: char *proto_name(int) 5) Child status handling is improved. 6) Handling of duplicate Event IDs is improved. Version 1.2: 1) Configuration option 'run_once' is equal to command-line option '--once' 2) Configuration option '--nice = level' or '-n = level' allows to reduce UNIX priority for each spool processor. The main process is not affected. Corresponding configuration option: 'nice = level' 3) mp_fast_alert is reimplemented to avoid QPL restrictions. 4) mp_acid_out is reimplemented to avoid QPL restrictions. 5) Fixed Classification Id calculation bug. 6) Cosmetic changes here and there. Version 1.3: 1) Dynamic buffer size calculation is now used in mp_acid_out plug-in. No more SQL errors on large packets! 2) Internal 1-minute timeout for each plug-in write operation is implemented. 3) Linear search is replaced by qsort/bsearch for the SID-MSG map. 4) Cosmetic changes.
Be the first person to add a text review.
Copyright © 2009 Geeknet, Inc. All rights reserved. Terms of Use
Thanks for your rating!
Would you also like to write a review?