Re: Snort3, syslog, and some additional questions
"Russ Combs \(rucombs\) via Snort-users" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <MN2PR11MB40488266F49B0EDFD0428EB1B7589@MN2PR11MB4048.namprd11.prod.outlook.com> |
James,
output alert_syslog: host is Snort 2 feature for Windows only. Snort 3 does not support Windows at present.
If you have that in your non-Windows Snort 2 config, you should be getting a warning like this in your startup output:
WARNING: etc/snort.conf (538) => Unrecognized syslog facility/priority: host=10.1.1.1:514,
Russ
________________________________
From: Snort-users <[email protected]> on behalf of Al Lewis (allewi) via Snort-users <[email protected]>
Sent: Monday, January 17, 2022 1:31 PM
To: [email protected] <[email protected]>; Snort <[email protected]>
Subject: Re: [Snort-users] Snort3, syslog, and some additional questions
I went into the source code to see if the option was there and not missing in the help section somehow.
The options listed in the snort documents are the ones available.
Albert Lewis
ENGINEER.SOFTWARE ENGINEERING
Cisco Systems Inc.
Email: [email protected]<mailto:[email protected]>
From: James Lay <[email protected]>
Reply-To: James Lay <[email protected]>
Date: Monday, January 17, 2022 at 12:46 PM
To: "Al Lewis (allewi)" <[email protected]>, Snort <[email protected]>
Subject: Re: [Snort-users] Snort3, syslog, and some additional questions
Thanks for the response Al. This brings up a couple points:
This is, in fact, a downgrade compared to snort 2. I've never understood new software version that remove functionality from the older version.
The fact that you had to go to the source code to get the info......why? Why isn't this information IN the snort docs? Does Cisco really expect users to have to go pouring into the source just got get an answer?
So....after that, please consider this a feature request...to put BACK the ability of being able to have snort3 natively syslog. Thanks Al!
James
On Mon, 2022-01-17 at 17:16 +0000, Al Lewis (allewi) wrote:
The logs are written locally. A quick glance at alert_syslog.cc suggests you may need rsyslogd (or something similar) running to have them forwarded elsewhere.
Albert Lewis
ENGINEER.SOFTWARE ENGINEERING
Cisco Systems Inc.
Email: [email protected]<mailto:[email protected]>
From: Snort-users <[email protected]> on behalf of James Lay <[email protected]>
Reply-To: James Lay <[email protected]>
Date: Monday, January 17, 2022 at 10:47 AM
To: Snort <[email protected]>
Subject: [Snort-users] Snort3, syslog, and some additional questions
So....after about 20 minutes of searching, I'm no closer to discovering where exactly to specify the syslog server. Some links I've stumbled on:
https://github.com/snort3/snort3/issues/216
and from:
https://www.snort.org/snort3
the entire bit about alert.syslog:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
alert_syslog
Help: output event to syslog
Type: logger
Usage: global
Configuration:
enum alert_syslog.facility = auth: part of priority applied to each message { auth | authpriv | daemon | user | local0 | local1 | local2 | local3 | local4 | local5 | local6 | local7 }
enum alert_syslog.level = info: part of priority applied to each message { emerg | alert | crit | err | warning | notice | info | debug }
multi alert_syslog.options: used to open the syslog connection { cons | ndelay | perror | pid }
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
No where does this specify how to specify the host.
So my questions:
Why are there NO examples of usage in the reference?
Where do I specify the server?
Thank you.
James
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette