Match SNORT IP alerts to specific URLs

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP











up vote
0
down vote

favorite












I have SNORT running on an Ubuntu 18.04 server. I have alerts firing off but the alert logs come through as IP addresses. I have a list of websites the system has visited throughout the day.



Is there a way of matching the URLs to the alerts?



One way I have thought is doing a domain -> IP translation and then matching the IP and time of visit with the alert log but is there a more accurate way?









share

























    up vote
    0
    down vote

    favorite












    I have SNORT running on an Ubuntu 18.04 server. I have alerts firing off but the alert logs come through as IP addresses. I have a list of websites the system has visited throughout the day.



    Is there a way of matching the URLs to the alerts?



    One way I have thought is doing a domain -> IP translation and then matching the IP and time of visit with the alert log but is there a more accurate way?









    share























      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      I have SNORT running on an Ubuntu 18.04 server. I have alerts firing off but the alert logs come through as IP addresses. I have a list of websites the system has visited throughout the day.



      Is there a way of matching the URLs to the alerts?



      One way I have thought is doing a domain -> IP translation and then matching the IP and time of visit with the alert log but is there a more accurate way?









      share













      I have SNORT running on an Ubuntu 18.04 server. I have alerts firing off but the alert logs come through as IP addresses. I have a list of websites the system has visited throughout the day.



      Is there a way of matching the URLs to the alerts?



      One way I have thought is doing a domain -> IP translation and then matching the IP and time of visit with the alert log but is there a more accurate way?







      ubuntu ip snort





      share












      share










      share



      share










      asked 6 mins ago









      Softey

      1032




      1032

























          active

          oldest

          votes











          Your Answer







          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "106"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          convertImagesToLinks: false,
          noModals: false,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: null,
          bindNavPrevention: true,
          postfix: "",
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













           

          draft saved


          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f478121%2fmatch-snort-ip-alerts-to-specific-urls%23new-answer', 'question_page');

          );

          Post as a guest



































          active

          oldest

          votes













          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes















           

          draft saved


          draft discarded















































           


          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f478121%2fmatch-snort-ip-alerts-to-specific-urls%23new-answer', 'question_page');

          );

          Post as a guest













































































          Popular posts from this blog

          Peggy Mitchell

          Palaiologos

          The Forum (Inglewood, California)