Getting Data In

How to send an IP and MAC address to a router filter file


I’m moving from custom software that writes a snort alert to a file that would filter the device on a router.

I’m not sure where to start but I’m hoping that there is a command line like “sendalert /var/log/$mac-$ip-filter.log” that will be processed upstream to the router by a cron job.

I would also like that a right-click on a Splunk search output to extract the same data and write to the file.

