Re: Read and parse Snort3 unified2 file

"Russ Combs \(rucombs\) via Snort-devel" <[email protected]> Sun, 21 Jul 2019 15:34:43 +0000
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <D959FDAE.6D447%[email protected]>
--===============8457337988186777477==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_D959FDAE6D447rucombsciscocom_"

--_000_D959FDAE6D447rucombsciscocom_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

You must set this to true:


  *   bool unified2.legacy_events =3D false: generate Snort 2.X style event=
s for barnyard2 compatibility

You can always develop your own log processor.  In that case you might want=
 to try the csv or json loggers instead.  They can include the packet data =
in base64.

From: Snort-devel <[email protected]<mailto:snort-devel-b=
[email protected]>> on behalf of Aden Snort via Snort-devel <snort-dev=
[email protected]<mailto:[email protected]>>
Reply-To: Aden Snort <[email protected]<mailto:[email protected]>>
Date: Thursday, July 18, 2019 at 8:27 AM
To: "[email protected]<mailto:[email protected]>" <snor=
[email protected]<mailto:[email protected]>>
Subject: [Snort-devel] Read and parse Snort3 unified2 file

Hi,
Currently I am reading Snort 2.x Unified2 file using Barnyard2.
Now I want to use Snort3 beta version. My question is that can I still use =
Barnyard2 for reading Snort3 unified2 file or there are some other ways. Al=
so can we develop our own program to read snort3 unified2 file.

Regards,
Aden Mehmud



--_000_D959FDAE6D447rucombsciscocom_
Content-Type: text/html; charset="us-ascii"
Content-ID: <[email protected]>
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
</head>
<body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; line-break:=
 after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Cali=
bri, sans-serif;">
<div>You must set this to true:</div>
<div><br>
</div>
<div>
<ul style=3D"margin-top: 0px; list-style-position: outside; font-family: Ge=
orgia, serif;">
<li style=3D"color: rgb(170, 170, 170);">
<p style=3D"margin-top: 0px; margin-bottom: 0.5em; color: black;">bool&nbsp=
;<strong style=3D"color: rgb(8, 49, 148);">unified2.legacy_events</strong>&=
nbsp;=3D false: generate Snort 2.X style events for barnyard2 compatibility=
</p>
</li></ul>
<div>You can always develop your own log processor. &nbsp;In that case you =
might want to try the csv or json loggers instead. &nbsp;They can include t=
he packet data in base64.</div>
</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div style=3D"font-family:Calibri; font-size:11pt; text-align:left; color:b=
lack; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM:=
 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid;=
 BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style=3D"font-weight:bold">From: </span>Snort-devel &lt;<a href=3D"ma=
ilto:[email protected]">[email protected]=
rg</a>&gt; on behalf of Aden Snort via Snort-devel &lt;<a href=3D"mailto:sn=
[email protected]">[email protected]</a>&gt;<br>
<span style=3D"font-weight:bold">Reply-To: </span>Aden Snort &lt;<a href=3D=
"mailto:[email protected]">[email protected]</a>&gt;<br>
<span style=3D"font-weight:bold">Date: </span>Thursday, July 18, 2019 at 8:=
27 AM<br>
<span style=3D"font-weight:bold">To: </span>&quot;<a href=3D"mailto:snort-d=
[email protected]">[email protected]</a>&quot; &lt;<a href=3D"=
mailto:[email protected]">[email protected]</a>&gt;<br>
<span style=3D"font-weight:bold">Subject: </span>[Snort-devel] Read and par=
se Snort3 unified2 file<br>
</div>
<div><br>
</div>
<div>
<div>
<div dir=3D"auto">
<div class=3D"gmail_quote" dir=3D"auto">
<div dir=3D"ltr" class=3D"gmail_attr">Hi,</div>
<div dir=3D"auto">
<div style=3D"font-family:sans-serif;font-size:12.8px" dir=3D"auto">
<div style=3D"width:328px;margin:16px 0px">
<div>
<div class=3D"m_-6072589203773029428elided-text">
<div dir=3D"auto">
<div dir=3D"auto">Currently I am reading Snort 2.x Unified2 file using Barn=
yard2.&nbsp;</div>
<div dir=3D"auto">Now I want to use Snort3 beta version. My question is tha=
t can I still use Barnyard2 for reading Snort3 unified2 file or there are s=
ome other ways. Also can we develop our own program to read snort3 unified2=
 file.</div>
<div dir=3D"auto"><br>
</div>
<div dir=3D"auto">Regards,</div>
<div dir=3D"auto">Aden Mehmud</div>
<div dir=3D"auto"><br>
</div>
</div>
</div>
</div>
</div>
<div style=3D"height:0px"></div>
</div>
<br>
</div>
</div>
</div>
</div>
</div>
</span>
</body>
</html>

--_000_D959FDAE6D447rucombsciscocom_--

--===============8457337988186777477==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!

--===============8457337988186777477==--