Re: Snort3, syslog, and some additional questions
James Lay <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
I'm sorry...I must have missed your question? What was it? On 2022-01-19 12:30, Russ Combs (rucombs) wrote: > James, > > I've responded to that. You haven't answered my questions. > > Russ > > ------------------------- > > FROM: James Lay <[email protected]> > SENT: Wednesday, January 19, 2022 1:50 PM > TO: Russ Combs (rucombs) <[email protected]> > CC: Snort <[email protected]>; Al Lewis (allewi) > <[email protected]> > SUBJECT: Re: [Snort-users] Snort3, syslog, and some additional > questions > > Wow...ok I guess I didn't specify this well at all. To sum it up: > > Snort 3 on linux...WHERE exactly do you specify the remote IP to send > snort alert output to? > > Here's the only info I have: > > 10.6. alert_syslog > -------------- > Help: output event to syslog > Type: logger > Usage: global > Configuration: > > * enum alert_syslog.facility = auth: part of priority applied to > each message { auth | authpriv | daemon | user | local0 | local1 > | local2 | local3 | local4 | local5 | local6 | local7 } > * enum alert_syslog.level = info: part of priority applied to each > message { emerg | alert | crit | err | warning | notice | info | > debug } > * multi alert_syslog.options: used to open the syslog connection { > cons | ndelay | perror | pid } > > There...that should do it..thank you :) > > James > > On 2022-01-19 11:23, Russ Combs (rucombs) wrote: >> James, >> >> I'm not sure we are talking about the same thing. I'm saying the >> difference in functionality is that Snort 2 emits a warning and > Snort >> 3 emits an error. That difference is intentional and will remain. >> >> To be clear, you are saying "output alert_syslog: host" is working >> for Snort 2 on Linux? Are you not seeing the warning on Linux like > the >> one shown below? Does it still work if you remove the host >> specification? >> >> Russ >> >> ------------------------- >> >> FROM: James Lay <[email protected]> >> SENT: Wednesday, January 19, 2022 10:31 AM >> TO: Russ Combs (rucombs) <[email protected]> >> CC: Snort <[email protected]>; Al Lewis (allewi) >> <[email protected]> >> SUBJECT: Re: [Snort-users] Snort3, syslog, and some additional >> questions >> >> This is on linux....no issues with snort 2, but I'd like to not have >> to >> futz with my rsyslog/syslog-ng configs just for snort. The snort 2 >> functionality should be the same in snort 3. In my opinion. >> >> James >> >> On 2022-01-18 07:58, Russ Combs (rucombs) wrote: >>> James, >>> >>> output alert_syslog: host is Snort 2 feature for Windows only. > Snort >> 3 >>> does not support Windows at present. >>> >>> If you have that in your non-Windows Snort 2 config, you should be >>> getting a warning like this in your startup output: >>> >>> WARNING: etc/snort.conf (538) => Unrecognized syslog >>> facility/priority: host=10.1.1.1:514, >>> >>> Russ >>> >>> ------------------------- >>> >>> FROM: Snort-users <[email protected]> on behalf > of >>> Al Lewis (allewi) via Snort-users <[email protected]> >>> SENT: Monday, January 17, 2022 1:31 PM >>> TO: [email protected] <[email protected]>; Snort >>> <[email protected]> >>> SUBJECT: Re: [Snort-users] Snort3, syslog, and some additional >>> questions >>> >>> I went into the source code to see if the option was there and not >>> missing in the help section somehow. >>> >>> The options listed in the snort documents are the ones available. >>> >>> ALBERT LEWIS >>> >>> ENGINEER.SOFTWARE ENGINEERING >>> >>> Cisco Systems Inc. >>> >>> Email: [email protected] >>> >>> FROM: James Lay <[email protected]> >>> REPLY-TO: James Lay <[email protected]> >>> DATE: Monday, January 17, 2022 at 12:46 PM >>> TO: "Al Lewis (allewi)" <[email protected]>, Snort >>> <[email protected]> >>> SUBJECT: Re: [Snort-users] Snort3, syslog, and some additional >>> questions >>> >>> Thanks for the response Al. This brings up a couple points: >>> >>> This is, in fact, a downgrade compared to snort 2. I've never >>> understood new software version that remove functionality from the >>> older version. >>> >>> The fact that you had to go to the source code to get the >>> info......why? Why isn't this information IN the snort docs? Does >>> Cisco really expect users to have to go pouring into the source > just >>> got get an answer? >>> >>> So....after that, please consider this a feature request...to put >> BACK >>> the ability of being able to have snort3 natively syslog. Thanks >> Al! >>> >>> James >>> >>> On Mon, 2022-01-17 at 17:16 +0000, Al Lewis (allewi) wrote: >>> >>>> The logs are written locally. A quick glance at alert_syslog.cc >>>> suggests you may need rsyslogd (or something similar) running to >>>> have them forwarded elsewhere. >>>> >>>> ALBERT LEWIS >>>> >>>> ENGINEER.SOFTWARE ENGINEERING >>>> >>>> Cisco Systems Inc. >>>> >>>> Email: [email protected] >>>> >>>> FROM: Snort-users <[email protected]> on behalf >> of >>>> James Lay <[email protected]> >>>> REPLY-TO: James Lay <[email protected]> >>>> DATE: Monday, January 17, 2022 at 10:47 AM >>>> TO: Snort <[email protected]> >>>> SUBJECT: [Snort-users] Snort3, syslog, and some additional >> questions >>>> >>>> >>>> So....after about 20 minutes of searching, I'm no closer to >>>> discovering where exactly to specify the syslog server. Some > links >>>> I've stumbled on: >>>> >>>> https://github.com/snort3/snort3/issues/216 >>>> >>>> and from: >>>> >>>> https://www.snort.org/snort3 >>>> >>>> the entire bit about alert.syslog: >>>> >>>> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >>>> >>>> alert_syslog >>>> >>>> Help: output event to syslog >>>> >>>> Type: logger >>>> >>>> Usage: global >>>> >>>> Configuration: >>>> >>>> enum alert_syslog.facility = auth: part of priority applied to > each >>>> message { auth | authpriv | daemon | user | local0 | local1 | >> local2 >>>> | local3 | local4 | local5 | local6 | local7 } >>>> >>>> enum alert_syslog.level = info: part of priority applied to each >>>> message { emerg | alert | crit | err | warning | notice | info | >>>> debug } >>>> >>>> multi alert_syslog.options: used to open the syslog connection { >>>> cons | ndelay | perror | pid } >>>> >>>> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >>>> >>>> No where does this specify how to specify the host. >>>> >>>> So my questions: >>>> >>>> Why are there NO examples of usage in the reference? >>>> >>>> Where do I specify the server? >>>> >>>> Thank you. >>>> >>>> James _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette