Wow!
I managed to get the file and folder handling working. And when i came back to this computer i saw that your code snippet did the same thing in about one third of the number of lines that I had
so needles to say im going to use your version.
Thank you very much for your help. (The feeling when these things finally work as intended is ...sweet).
There's only one tiny problem left.
Does anyone know how i actually manage to get it to kick off when snort alerts? After a few tests I dont seem to get that part working.
i.e I dont really understand the part: "alert_triggered -eq 1".
Would it require me to set up some variable(alert_triggered) that is hooked on to snort and listens for alerts? (Or is this alerter functionality already built-in and waiting for me somewhere in linux)
Any ideas on how this can be done? (Or did i miss something in the example?)
If i need to somehow hook a listener to snort...well im kind of lost so examples will be immensely appreciated
.
/F