support for barnyard's payload_encoding syslog option?

Jason Haar via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CAFChrgLZf8fjFPnfRH1nBZUf0V9ZOXFxNsxuMOdeK_yMVEukiQ@mail.gmail.com>
Hi there

I've been using barnyard for years because it has this
cool "payload_encoding" option for syslog. This enables it to log (via
syslog) the packet content rather than just the "ip:port" data.

eg

Jan  3 01:07:24 snort.srv snort[128172]: | [SNORTIDS[LOG]: [barnyard2-eth1]
] || Jan  3 01:07:24 3 [1:58737:3] SERVER-OTHER Apache Log4j logging remote
code execution attempt || not-suspicious || 6 a.b.c.d w.x.y.z 4 20 0 407
64122 2 0 23584 0 || 47901 80 2456844058 4162760743 5 0 24 42340 15512 0 ||
421 .PV.fF..&lt;[email protected].\ .|.T..&lt;....P.pw....'P..d&lt;...GET
/?test=%24%7Blog4jstring%3Aldap%3A%2F%
2Fsecurityscanner.cyber-risk.upguard.com%3A443%2Fxxxx%7D HTTP/1.1..Host:
web.srv.name..user-agent: Mozilla/1.0 ${log4jtest:ldap://
securityscanner.cyber-risk.upguard.com:443/nxxx/1.1..accept-encoding:
gzip..Connection: close.... ||   |

 Really useful for realtime SOAR activity as your SOAR can see (say) that
attack against your web server was actually from an user-agent you have
previously reviewed and whitelisted. Turns slow human/manual secops
activity into an automated realtime response

As snort already supports syslog, it's a PITA to install barnyard just to
gain that extra feature... I was wondering what the appetite would be to
see this supported as an option within core snort?




-- 
Cheers

Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +1 408 481 8171
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.