Skip to content
This repository has been archived by the owner on Apr 16, 2021. It is now read-only.
Doug Burks edited this page May 20, 2015 · 31 revisions
  • Developed by Dustin Webber

  • Web 2.0, Ajax, Ruby-on-Rails

  • Snorby has its own MySQL database (separate from the Sguil and ELSA databases).

  • The Snorby database only stores NIDS alerts from Snort or Suricata.

  • Pivot from a NIDS alert in Snorby to CapME to access full packet capture

  • Pivot from an IP address in Snorby to ELSA for related logs (Bro logs, OSSEC logs, syslog).

  • For more information, please see:
    https://www.snorby.org/

Clone this wiki locally