Professional Documents
Culture Documents
Automatic classify/catagorize? View packet data? View Rule within GUI? Export Event Data? Authentication System? Graph Options? Graph Alerts by Date? Graph Alerts by Time? Graph # of Alerts by Time? Graph Alerts by Src IP? Graph Alerts by Dst IP? Graph Alerts by Severity/ Category? Graph Alerts by Signature? Graph Alerts by Src Port? Graph Alerts by Dst Port? Graph Alerts by Country? Plot Alerts on World Map?
no yes yes yes (email only) yes pie/bar/line/worldmap yes yes yes (bar only) yes yes no Yes(using Alert Groups) yes yes yes yes
Snorby 2.3.9 Yes (High/Med/Low/ Events vs. Time Severity Count vs Time Protocol Count vs Time Signatures Pie Chart Sources Pie Chart Destinations Pie Chart Top 5 Sensors Top 5 Users Last 5 Unique Events Analyst Classified Events) yes yes yes yes (email/xml) yes preset line/pie yes (presets only) yes (presets only) no yes (pie only) yes (pie only) yes yes (pie only) no no no no
SQueRT 0.9.2 Yes (Brief Events by Sensor Events by Category Top Signatures Top Source IP's Top Destination IP's)
yes yes yes no yes preset pie/bar yes yes yes (heatmap) yes (bar only) yes (bar only) yes yes yes yes yes yes (bar only) (bar only) (bar only) (pie only)
Special Features
Can export a pdf report that includes: Events vs. Time Severity Count vs Time Protocol Count vs Time Top 15 Signatures Top 10 Source Addresses Top 10 Dest Addresses. Integrates with some 3rd party apps Hotkey support Custom lookups via API Community/Developer yes git ruby rails imagemagick wkhtmltopdf Usually phusion passenger
County Alerts Wordmap. Dashboard includes timeframe of last event. Graphviz graphs.
Community only yes php pear-php php Image-Graph php Image-Canvas php mail none
Community/Developer yes php TCL, TclX Graphviz (with PNG) Perl Text::CSV
sguildb snort_agent