Re: Read and parse Snort3 unified2 file
"Russ Combs \(rucombs\) via Snort-devel" <[email protected]> Sun, 21 Jul 2019 15:34:43 +0000
| Newsgroups | gmane.comp.security.ids.snort.devel |
|---|---|
| Message-ID | <D959FDAE.6D447%[email protected]> |
--===============8457337988186777477== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_D959FDAE6D447rucombsciscocom_" --_000_D959FDAE6D447rucombsciscocom_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable You must set this to true: * bool unified2.legacy_events =3D false: generate Snort 2.X style event= s for barnyard2 compatibility You can always develop your own log processor. In that case you might want= to try the csv or json loggers instead. They can include the packet data = in base64. From: Snort-devel <[email protected]<mailto:snort-devel-b= [email protected]>> on behalf of Aden Snort via Snort-devel <snort-dev= [email protected]<mailto:[email protected]>> Reply-To: Aden Snort <[email protected]<mailto:[email protected]>> Date: Thursday, July 18, 2019 at 8:27 AM To: "[email protected]<mailto:[email protected]>" <snor= [email protected]<mailto:[email protected]>> Subject: [Snort-devel] Read and parse Snort3 unified2 file Hi, Currently I am reading Snort 2.x Unified2 file using Barnyard2. Now I want to use Snort3 beta version. My question is that can I still use = Barnyard2 for reading Snort3 unified2 file or there are some other ways. Al= so can we develop our own program to read snort3 unified2 file. Regards, Aden Mehmud --_000_D959FDAE6D447rucombsciscocom_ Content-Type: text/html; charset="us-ascii" Content-ID: <[email protected]> Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"= > </head> <body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; line-break:= after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Cali= bri, sans-serif;"> <div>You must set this to true:</div> <div><br> </div> <div> <ul style=3D"margin-top: 0px; list-style-position: outside; font-family: Ge= orgia, serif;"> <li style=3D"color: rgb(170, 170, 170);"> <p style=3D"margin-top: 0px; margin-bottom: 0.5em; color: black;">bool = ;<strong style=3D"color: rgb(8, 49, 148);">unified2.legacy_events</strong>&= nbsp;=3D false: generate Snort 2.X style events for barnyard2 compatibility= </p> </li></ul> <div>You can always develop your own log processor. In that case you = might want to try the csv or json loggers instead. They can include t= he packet data in base64.</div> </div> <div><br> </div> <span id=3D"OLK_SRC_BODY_SECTION"> <div style=3D"font-family:Calibri; font-size:11pt; text-align:left; color:b= lack; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM:= 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid;= BORDER-RIGHT: medium none; PADDING-TOP: 3pt"> <span style=3D"font-weight:bold">From: </span>Snort-devel <<a href=3D"ma= ilto:[email protected]">[email protected]= rg</a>> on behalf of Aden Snort via Snort-devel <<a href=3D"mailto:sn= [email protected]">[email protected]</a>><br> <span style=3D"font-weight:bold">Reply-To: </span>Aden Snort <<a href=3D= "mailto:[email protected]">[email protected]</a>><br> <span style=3D"font-weight:bold">Date: </span>Thursday, July 18, 2019 at 8:= 27 AM<br> <span style=3D"font-weight:bold">To: </span>"<a href=3D"mailto:snort-d= [email protected]">[email protected]</a>" <<a href=3D"= mailto:[email protected]">[email protected]</a>><br> <span style=3D"font-weight:bold">Subject: </span>[Snort-devel] Read and par= se Snort3 unified2 file<br> </div> <div><br> </div> <div> <div> <div dir=3D"auto"> <div class=3D"gmail_quote" dir=3D"auto"> <div dir=3D"ltr" class=3D"gmail_attr">Hi,</div> <div dir=3D"auto"> <div style=3D"font-family:sans-serif;font-size:12.8px" dir=3D"auto"> <div style=3D"width:328px;margin:16px 0px"> <div> <div class=3D"m_-6072589203773029428elided-text"> <div dir=3D"auto"> <div dir=3D"auto">Currently I am reading Snort 2.x Unified2 file using Barn= yard2. </div> <div dir=3D"auto">Now I want to use Snort3 beta version. My question is tha= t can I still use Barnyard2 for reading Snort3 unified2 file or there are s= ome other ways. Also can we develop our own program to read snort3 unified2= file.</div> <div dir=3D"auto"><br> </div> <div dir=3D"auto">Regards,</div> <div dir=3D"auto">Aden Mehmud</div> <div dir=3D"auto"><br> </div> </div> </div> </div> </div> <div style=3D"height:0px"></div> </div> <br> </div> </div> </div> </div> </div> </span> </body> </html> --_000_D959FDAE6D447rucombsciscocom_-- --===============8457337988186777477== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-devel mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-devel Please visit http://blog.snort.org for the latest news about Snort! --===============8457337988186777477==--