I’m moving from custom software that writes a snort alert to a file that would filter the device on a router.
I’m not sure where to start but I’m hoping that there is a command line like “sendalert /var/log/$mac-$ip-filter.log” that will be processed upstream to the router by a cron job.
I would also like that a right-click on a Splunk search output to extract the same data and write to the file.