Line: 1 to 1 | ||||||||
---|---|---|---|---|---|---|---|---|
| ||||||||
Line: 12 to 12 | ||||||||
$EXTERNAL_NET/$HOME_NET support - Possibly other variables to further identify where the traffic is coming from and what to do with it. | ||||||||
Changed: | ||||||||
< < | Syslog/UDP replay add on - A program, separate and external to Sagan, that'll 'sniff' the network interface for UDP/514 Syslog traffic. If traffic is seen, capture the packet and reply it to another Syslog server. Such a program is useful in pre-setup syslog environments.(Idea credited to Bruce Wink). | |||||||
> > | ||||||||
Need snmptrapd rules - "snmptrapd" write out to syslog. Need rules. | ||||||||
Line: 22 to 22 | ||||||||
Stats - Periodic stats dumped to the /var/log/sagan/sagan.log. Top IP's, SIDs, etc. | ||||||||
Changed: | ||||||||
< < | PIX/ASA parser - to extract PIX/ASA IP/Port information | |||||||
> > | | |||||||
Sguid agent ... Could be cool? |