Match SNORT IP alerts to specific URLs

Clash Royale CLAN TAG#URR8PPP
up vote
0
down vote
favorite
I have SNORT running on an Ubuntu 18.04 server. I have alerts firing off but the alert logs come through as IP addresses. I have a list of websites the system has visited throughout the day.
Is there a way of matching the URLs to the alerts?
One way I have thought is doing a domain -> IP translation and then matching the IP and time of visit with the alert log but is there a more accurate way?
ubuntu ip snort
add a comment |Â
up vote
0
down vote
favorite
I have SNORT running on an Ubuntu 18.04 server. I have alerts firing off but the alert logs come through as IP addresses. I have a list of websites the system has visited throughout the day.
Is there a way of matching the URLs to the alerts?
One way I have thought is doing a domain -> IP translation and then matching the IP and time of visit with the alert log but is there a more accurate way?
ubuntu ip snort
add a comment |Â
up vote
0
down vote
favorite
up vote
0
down vote
favorite
I have SNORT running on an Ubuntu 18.04 server. I have alerts firing off but the alert logs come through as IP addresses. I have a list of websites the system has visited throughout the day.
Is there a way of matching the URLs to the alerts?
One way I have thought is doing a domain -> IP translation and then matching the IP and time of visit with the alert log but is there a more accurate way?
ubuntu ip snort
I have SNORT running on an Ubuntu 18.04 server. I have alerts firing off but the alert logs come through as IP addresses. I have a list of websites the system has visited throughout the day.
Is there a way of matching the URLs to the alerts?
One way I have thought is doing a domain -> IP translation and then matching the IP and time of visit with the alert log but is there a more accurate way?
ubuntu ip snort
ubuntu ip snort
asked 6 mins ago
Softey
1032
1032
add a comment |Â
add a comment |Â
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f478121%2fmatch-snort-ip-alerts-to-specific-urls%23new-answer', 'question_page');
);
Post as a guest
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password