[Sguil-cvs] sguil/server sguild.email,1.2,1.3
Status: Beta
Brought to you by:
bamm
From: Bamm V. <ba...@us...> - 2006-01-18 19:23:09
|
Update of /cvsroot/sguil/sguil/server In directory sc8-pr-cvs1.sourceforge.net:/tmp/cvs-serv12824 Modified Files: sguild.email Log Message: Added %sig_id (signature id) and %class (snort classification) to the email vars. Index: sguild.email =================================================================== RCS file: /cvsroot/sguil/sguil/server/sguild.email,v retrieving revision 1.2 retrieving revision 1.3 diff -C2 -d -r1.2 -r1.3 *** sguild.email 24 Oct 2005 15:44:59 -0000 1.2 --- sguild.email 18 Jan 2006 19:23:00 -0000 1.3 *************** *** 26,30 **** # %sn=sensor name %msg=snort message %t=timestamp %sip=src ip %dip=dest ip # %sp=src port %dp=dst port %shost=src hostname %dhost=dst hostname ! # %eid=event id (sid.cid) set EMAIL_MSG "\[%t\] ALERT %eid from %sn: %msg. %sip (%shost):%sp -> %dip (%dhost):%dp" --- 26,30 ---- # %sn=sensor name %msg=snort message %t=timestamp %sip=src ip %dip=dest ip # %sp=src port %dp=dst port %shost=src hostname %dhost=dst hostname ! # %eid=event id (sid.cid) %sig_id=(signature ID) %class=(snort classification) set EMAIL_MSG "\[%t\] ALERT %eid from %sn: %msg. %sip (%shost):%sp -> %dip (%dhost):%dp" |