<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Winids Snort in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Winids-Snort/m-p/60397#M3617</link>
    <description>&lt;P&gt;Hi, I have a IDS system running snort on WINIDS (Win7). How do I get splunk to connect and collect info ?&lt;/P&gt;</description>
    <pubDate>Mon, 30 Jan 2012 13:01:16 GMT</pubDate>
    <dc:creator>pcarron</dc:creator>
    <dc:date>2012-01-30T13:01:16Z</dc:date>
    <item>
      <title>Winids Snort</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Winids-Snort/m-p/60397#M3617</link>
      <description>&lt;P&gt;Hi, I have a IDS system running snort on WINIDS (Win7). How do I get splunk to connect and collect info ?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2012 13:01:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Winids-Snort/m-p/60397#M3617</guid>
      <dc:creator>pcarron</dc:creator>
      <dc:date>2012-01-30T13:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Winids Snort</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Winids-Snort/m-p/60398#M3618</link>
      <description>&lt;P&gt;I have no experience with WINIDS myself, but looking at the information pages it seems it comes preconfigured with Snort logging to a local MySQL database. In order to have Splunk read it, you will need to configure to log either to a file or via syslog (I found instructions on the latter here: &lt;A href="http://www.winsnort.com/index.php?module=Pages&amp;amp;func=display&amp;amp;pageid=21"&gt;http://www.winsnort.com/index.php?module=Pages&amp;amp;func=display&amp;amp;pageid=21&lt;/A&gt;). Reading events from a MySQL database is not supported, mostly because of the lack of a unified way to query databases from Splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2012 13:51:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Winids-Snort/m-p/60398#M3618</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-01-30T13:51:59Z</dc:date>
    </item>
  </channel>
</rss>

