Snort 2.9.x ruletype logging output question

Fatih USTA via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
Hi

I'm trying to use "ruletype" to multiple logging output for specific rules.
I defined a "ruletype" and I used in the rule. I can't see any output.

Are there any idea?

output unified2: filename snort_unified.log, limit 128

ruletype my_alert {
     type alert
     output unified2: filename snort_unified.log, limit 128
     output alert_syslog: log_auth log_alert
}

my_alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET 
WEB_SPECIFIC_APPS User Agent (SQLi Injection / Scanning)"; 
flow:established,to_server; content:"User-Agent|3a 20|testitest"; 
http_header; fast_pattern; 
reference:url,en.wikipedia.org/wiki/SQL_injection; 
classtype:web-application-attack; sid:2023351; rev:1; 
metadata:attack_target SQL_Server, created_at 2016_10_19, deployment 
Datacenter, performance_impact Low, signature_severity Major, updated_at 
2020_07_31;)


I tested on snort 2.9.9.0 and 2.9.19.


Thanks.

-- 
Fatih USTA

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.