Snort 2.9.x ruletype logging output question
Fatih USTA via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Hi
I'm trying to use "ruletype" to multiple logging output for specific rules.
I defined a "ruletype" and I used in the rule. I can't see any output.
Are there any idea?
output unified2: filename snort_unified.log, limit 128
ruletype my_alert {
type alert
output unified2: filename snort_unified.log, limit 128
output alert_syslog: log_auth log_alert
}
my_alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET
WEB_SPECIFIC_APPS User Agent (SQLi Injection / Scanning)";
flow:established,to_server; content:"User-Agent|3a 20|testitest";
http_header; fast_pattern;
reference:url,en.wikipedia.org/wiki/SQL_injection;
classtype:web-application-attack; sid:2023351; rev:1;
metadata:attack_target SQL_Server, created_at 2016_10_19, deployment
Datacenter, performance_impact Low, signature_severity Major, updated_at
2020_07_31;)
I tested on snort 2.9.9.0 and 2.9.19.
Thanks.
--
Fatih USTA
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette