I need to give a presentation regarding Snort and Security Auditing. I have recently learned to configure Snort as a NIDS. I want to know is there any way I can configure Snort as an HIDS? If I am updating variable HOME_NET to my IP, it'll log all ingress and egress traffic but is there a way to make it log all application and events occurring in a system?
Thank you in advance.