Re: Snort3, syslog, and some additional questions
"Russ Combs \(rucombs\) via Snort-users" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <MN2PR11MB4048329EB9174E00A1B7B1CAB7599@MN2PR11MB4048.namprd11.prod.outlook.com> |
James, I'm not sure we are talking about the same thing. I'm saying the difference in functionality is that Snort 2 emits a warning and Snort 3 emits an error. That difference is intentional and will remain. To be clear, you are saying "output alert_syslog: host" is working for Snort 2 on Linux? Are you not seeing the warning on Linux like the one shown below? Does it still work if you remove the host specification? Russ ________________________________ From: James Lay <[email protected]> Sent: Wednesday, January 19, 2022 10:31 AM To: Russ Combs (rucombs) <[email protected]> Cc: Snort <[email protected]>; Al Lewis (allewi) <[email protected]> Subject: Re: [Snort-users] Snort3, syslog, and some additional questions This is on linux....no issues with snort 2, but I'd like to not have to futz with my rsyslog/syslog-ng configs just for snort. The snort 2 functionality should be the same in snort 3. In my opinion. James On 2022-01-18 07:58, Russ Combs (rucombs) wrote: > James, > > output alert_syslog: host is Snort 2 feature for Windows only. Snort 3 > does not support Windows at present. > > If you have that in your non-Windows Snort 2 config, you should be > getting a warning like this in your startup output: > > WARNING: etc/snort.conf (538) => Unrecognized syslog > facility/priority: host=10.1.1.1:514, > > Russ > > ------------------------- > > FROM: Snort-users <[email protected]> on behalf of > Al Lewis (allewi) via Snort-users <[email protected]> > SENT: Monday, January 17, 2022 1:31 PM > TO: [email protected] <[email protected]>; Snort > <[email protected]> > SUBJECT: Re: [Snort-users] Snort3, syslog, and some additional > questions > > I went into the source code to see if the option was there and not > missing in the help section somehow. > > The options listed in the snort documents are the ones available. > > ALBERT LEWIS > > ENGINEER.SOFTWARE ENGINEERING > > Cisco Systems Inc. > > Email: [email protected] > > FROM: James Lay <[email protected]> > REPLY-TO: James Lay <[email protected]> > DATE: Monday, January 17, 2022 at 12:46 PM > TO: "Al Lewis (allewi)" <[email protected]>, Snort > <[email protected]> > SUBJECT: Re: [Snort-users] Snort3, syslog, and some additional > questions > > Thanks for the response Al. This brings up a couple points: > > This is, in fact, a downgrade compared to snort 2. I've never > understood new software version that remove functionality from the > older version. > > The fact that you had to go to the source code to get the > info......why? Why isn't this information IN the snort docs? Does > Cisco really expect users to have to go pouring into the source just > got get an answer? > > So....after that, please consider this a feature request...to put BACK > the ability of being able to have snort3 natively syslog. Thanks Al! > > James > > On Mon, 2022-01-17 at 17:16 +0000, Al Lewis (allewi) wrote: > >> The logs are written locally. A quick glance at alert_syslog.cc >> suggests you may need rsyslogd (or something similar) running to >> have them forwarded elsewhere. >> >> ALBERT LEWIS >> >> ENGINEER.SOFTWARE ENGINEERING >> >> Cisco Systems Inc. >> >> Email: [email protected] >> >> FROM: Snort-users <[email protected]> on behalf of >> James Lay <[email protected]> >> REPLY-TO: James Lay <[email protected]> >> DATE: Monday, January 17, 2022 at 10:47 AM >> TO: Snort <[email protected]> >> SUBJECT: [Snort-users] Snort3, syslog, and some additional questions >> >> >> So....after about 20 minutes of searching, I'm no closer to >> discovering where exactly to specify the syslog server. Some links >> I've stumbled on: >> >> https://github.com/snort3/snort3/issues/216 >> >> and from: >> >> https://www.snort.org/snort3 >> >> the entire bit about alert.syslog: >> >> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >> >> alert_syslog >> >> Help: output event to syslog >> >> Type: logger >> >> Usage: global >> >> Configuration: >> >> enum alert_syslog.facility = auth: part of priority applied to each >> message { auth | authpriv | daemon | user | local0 | local1 | local2 >> | local3 | local4 | local5 | local6 | local7 } >> >> enum alert_syslog.level = info: part of priority applied to each >> message { emerg | alert | crit | err | warning | notice | info | >> debug } >> >> multi alert_syslog.options: used to open the syslog connection { >> cons | ndelay | perror | pid } >> >> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >> >> No where does this specify how to specify the host. >> >> So my questions: >> >> Why are there NO examples of usage in the reference? >> >> Where do I specify the server? >> >> Thank you. >> >> James _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette