J'utilise Snort version 2.8.5.2 sous une Debian Linux, chaque fois que je reçois le rapport journalier par mail qui est :
- Code: Tout sélectionner
Events from same host to same destination using same method
=========================================================================
# of from to method
=========================================================================
{...}
Percentage and number of events from a host to a destination
============================================================
% # of from to
============================================================
{...}
Percentage and number of events from one host to any with same method
==============================================================
% # of from method
==============================================================
{...}
Percentage and number of events to one certain host
=================================================================
% # of to method
=================================================================
{...}
The distribution of event methods
===============================================
% # of method
===============================================
{...}
Et je voudrais savoir s'il est possible d'avoir que la dernière parti du rapport, à savoir :
- Code: Tout sélectionner
The distribution of event methods
===============================================
% # of method
===============================================
{...}
Merci de votre réponse.
spz.