Re: Snort3, syslog, and some additional questions

James Lay <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <562765c6ca7f4df4755ea2384a953f31801546da.camel@slave-tothe-box.net>
Thanks for the response Al.  This brings up a couple points:

This is, in fact, a downgrade compared to snort 2.  I've never
understood new software version that remove functionality from the
older version.

The fact that you had to go to the source code to get the
info......why?  Why isn't this information IN the snort docs?  Does
Cisco really expect users to have to go pouring into the source just
got get an answer?


So....after that, please consider this a feature request...to put BACK
the ability of being able to have snort3 natively syslog.  Thanks Al!

James

On Mon, 2022-01-17 at 17:16 +0000, Al Lewis (allewi) wrote:
> The logs are written locally. A quick glance at alert_syslog.cc
> suggests you may need rsyslogd (or something similar) running to have
> them forwarded elsewhere.
>  
>  
> 
> Albert Lewis
> ENGINEER.SOFTWARE ENGINEERING
> Cisco Systems Inc.
> Email: [email protected]
>  
> 
>  
>  
> 
> From: Snort-users <[email protected]> on behalf of
> James Lay <[email protected]>
> 
> Reply-To: James Lay <[email protected]>
> 
> Date: Monday, January 17, 2022 at 10:47 AM
> 
> To: Snort <[email protected]>
> 
> Subject: [Snort-users] Snort3, syslog, and some additional questions
> 
> 
>  
> 
> 
> So....after about 20 minutes of searching, I'm no closer to
> discovering where exactly to specify the syslog server.  Some links
> I've stumbled on:
> 
> 
>  
> 
> 
> https://github.com/snort3/snort3/issues/216
> 
> 
>  
> 
> 
> and from:
> 
> 
> https://www.snort.org/snort3
> 
> 
>  
> 
> 
> the entire bit about alert.syslog:
> 
> 
> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> 
> 
> alert_syslog
> 
> 
> Help: output event to syslog
> 
> 
>  
> 
> 
> Type: logger
> 
> 
>  
> 
> 
> Usage: global
> 
> 
>  
> 
> 
> Configuration:
> 
> 
>  
> 
> 
> enum alert_syslog.facility = auth: part of priority applied to each
> message { auth | authpriv | daemon | user | local0 | local1 | local2
> | local3 | local4 | local5 | local6 | local7 }
> 
> 
> enum alert_syslog.level = info: part of priority applied to each
> message { emerg | alert | crit | err | warning | notice | info |
> debug }
> 
> 
> multi alert_syslog.options: used to open the syslog connection { cons
> | ndelay | perror | pid }
> 
> 
> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> 
> 
>  
> 
> 
> No where does this specify how to specify the host.
> 
> 
>  
> 
> 
> So my questions:
> 
> 
> Why are there NO examples of usage in the reference?
> 
> 
> Where do I specify the server?
> 
> 
>  
> 
> 
> Thank you.
> 
> 
>  
> 
> 
> James
> 
> 
>  
> 
> 
> 
>

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.