Re: Snort3, syslog, and some additional questions
James Lay <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Wow...ok I guess I didn't specify this well at all. To sum it up:
Snort 3 on linux...WHERE exactly do you specify the remote IP to send
snort alert output to?
Here's the only info I have:
10.6. alert_syslog
--------------
Help: output event to syslog
Type: logger
Usage: global
Configuration:
* enum alert_syslog.facility = auth: part of priority applied to
each message { auth | authpriv | daemon | user | local0 | local1
| local2 | local3 | local4 | local5 | local6 | local7 }
* enum alert_syslog.level = info: part of priority applied to each
message { emerg | alert | crit | err | warning | notice | info |
debug }
* multi alert_syslog.options: used to open the syslog connection {
cons | ndelay | perror | pid }
There...that should do it..thank you :)
James
On 2022-01-19 11:23, Russ Combs (rucombs) wrote:
> James,
>
> I'm not sure we are talking about the same thing. I'm saying the
> difference in functionality is that Snort 2 emits a warning and Snort
> 3 emits an error. That difference is intentional and will remain.
>
> To be clear, you are saying "output alert_syslog: host" is working
> for Snort 2 on Linux? Are you not seeing the warning on Linux like the
> one shown below? Does it still work if you remove the host
> specification?
>
> Russ
>
> -------------------------
>
> FROM: James Lay <[email protected]>
> SENT: Wednesday, January 19, 2022 10:31 AM
> TO: Russ Combs (rucombs) <[email protected]>
> CC: Snort <[email protected]>; Al Lewis (allewi)
> <[email protected]>
> SUBJECT: Re: [Snort-users] Snort3, syslog, and some additional
> questions
>
> This is on linux....no issues with snort 2, but I'd like to not have
> to
> futz with my rsyslog/syslog-ng configs just for snort. The snort 2
> functionality should be the same in snort 3. In my opinion.
>
> James
>
> On 2022-01-18 07:58, Russ Combs (rucombs) wrote:
>> James,
>>
>> output alert_syslog: host is Snort 2 feature for Windows only. Snort
> 3
>> does not support Windows at present.
>>
>> If you have that in your non-Windows Snort 2 config, you should be
>> getting a warning like this in your startup output:
>>
>> WARNING: etc/snort.conf (538) => Unrecognized syslog
>> facility/priority: host=10.1.1.1:514,
>>
>> Russ
>>
>> -------------------------
>>
>> FROM: Snort-users <[email protected]> on behalf of
>> Al Lewis (allewi) via Snort-users <[email protected]>
>> SENT: Monday, January 17, 2022 1:31 PM
>> TO: [email protected] <[email protected]>; Snort
>> <[email protected]>
>> SUBJECT: Re: [Snort-users] Snort3, syslog, and some additional
>> questions
>>
>> I went into the source code to see if the option was there and not
>> missing in the help section somehow.
>>
>> The options listed in the snort documents are the ones available.
>>
>> ALBERT LEWIS
>>
>> ENGINEER.SOFTWARE ENGINEERING
>>
>> Cisco Systems Inc.
>>
>> Email: [email protected]
>>
>> FROM: James Lay <[email protected]>
>> REPLY-TO: James Lay <[email protected]>
>> DATE: Monday, January 17, 2022 at 12:46 PM
>> TO: "Al Lewis (allewi)" <[email protected]>, Snort
>> <[email protected]>
>> SUBJECT: Re: [Snort-users] Snort3, syslog, and some additional
>> questions
>>
>> Thanks for the response Al. This brings up a couple points:
>>
>> This is, in fact, a downgrade compared to snort 2. I've never
>> understood new software version that remove functionality from the
>> older version.
>>
>> The fact that you had to go to the source code to get the
>> info......why? Why isn't this information IN the snort docs? Does
>> Cisco really expect users to have to go pouring into the source just
>> got get an answer?
>>
>> So....after that, please consider this a feature request...to put
> BACK
>> the ability of being able to have snort3 natively syslog. Thanks
> Al!
>>
>> James
>>
>> On Mon, 2022-01-17 at 17:16 +0000, Al Lewis (allewi) wrote:
>>
>>> The logs are written locally. A quick glance at alert_syslog.cc
>>> suggests you may need rsyslogd (or something similar) running to
>>> have them forwarded elsewhere.
>>>
>>> ALBERT LEWIS
>>>
>>> ENGINEER.SOFTWARE ENGINEERING
>>>
>>> Cisco Systems Inc.
>>>
>>> Email: [email protected]
>>>
>>> FROM: Snort-users <[email protected]> on behalf
> of
>>> James Lay <[email protected]>
>>> REPLY-TO: James Lay <[email protected]>
>>> DATE: Monday, January 17, 2022 at 10:47 AM
>>> TO: Snort <[email protected]>
>>> SUBJECT: [Snort-users] Snort3, syslog, and some additional
> questions
>>>
>>>
>>> So....after about 20 minutes of searching, I'm no closer to
>>> discovering where exactly to specify the syslog server. Some links
>>> I've stumbled on:
>>>
>>> https://github.com/snort3/snort3/issues/216
>>>
>>> and from:
>>>
>>> https://www.snort.org/snort3
>>>
>>> the entire bit about alert.syslog:
>>>
>>> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>>>
>>> alert_syslog
>>>
>>> Help: output event to syslog
>>>
>>> Type: logger
>>>
>>> Usage: global
>>>
>>> Configuration:
>>>
>>> enum alert_syslog.facility = auth: part of priority applied to each
>>> message { auth | authpriv | daemon | user | local0 | local1 |
> local2
>>> | local3 | local4 | local5 | local6 | local7 }
>>>
>>> enum alert_syslog.level = info: part of priority applied to each
>>> message { emerg | alert | crit | err | warning | notice | info |
>>> debug }
>>>
>>> multi alert_syslog.options: used to open the syslog connection {
>>> cons | ndelay | perror | pid }
>>>
>>> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>>>
>>> No where does this specify how to specify the host.
>>>
>>> So my questions:
>>>
>>> Why are there NO examples of usage in the reference?
>>>
>>> Where do I specify the server?
>>>
>>> Thank you.
>>>
>>> James
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette