- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to send an IP and MAC address to a router filter file
![jcrochon jcrochon](https://community.splunk.com/legacyfs/online/avatars/192769.jpg)
jcrochon
Explorer
07-30-2018
05:37 PM
I’m moving from custom software that writes a snort alert to a file that would filter the device on a router.
I’m not sure where to start but I’m hoping that there is a command line like “sendalert /var/log/$mac-$ip-filter.log” that will be processed upstream to the router by a cron job.
I would also like that a right-click on a Splunk search output to extract the same data and write to the file.
![](/skins/images/FE4825B2128CA5F641629E007E333890/responsive_peak/images/icon_anonymous_message.png)