Fwd: Snort 2.9.x ruletype logging output question

Fatih USTA via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
Hi

First off all i didn't get your answer to my email box, so I copied your 
answer to here from the web.

I'm not asking signature specific question. I'm asking configuration 
question.
Normally signature matches traffic and I saw at the log, so there is no 
problem here.

Snort doesn't log for the traffic when I want to use different rule 
action for multiple logging output.
I think, there is a bug here or what am I missing for correct configuration?

I'm fallowing this documentation.
http://manual-snort-org.s3-website-us-east-1.amazonaws.com/node29.html#SECTION00421000000000000000

Thanks.

-----

Dorian ROSSE dorianbrice at hotmail.fr
Wed Jan 26 12:06:40 UTC 2022
Previous message (by thread): [Snort-users] Snort 2.9.x ruletype logging 
output question
Next message (by thread): [Snort-users] snort3: correct and effective 
number of packet threads
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

Hello,


You should subscribe to snort sig and ask your question to snort sig,

This is a rule questions so you should ask to there,

Regards.


Dorian Rosse.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: 
<https://lists.snort.org/pipermail/snort-users/attachments/20220126/e74da81b/attachment.htm>



-------- Forwarded Message --------
Subject: 	Snort 2.9.x ruletype logging output question
Date: 	Tue, 25 Jan 2022 12:06:29 +0300
From: 	Fatih USTA <[email protected]>
To: 	[email protected]



Hi

I'm trying to use "ruletype" to multiple logging output for specific rules.
I defined a "ruletype" and I used in the rule. I can't see any output.

Are there any idea?

output unified2: filename snort_unified.log, limit 128

ruletype my_alert {
     type alert
     output unified2: filename snort_unified.log, limit 128
     output alert_syslog: log_auth log_alert
}

my_alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET 
WEB_SPECIFIC_APPS User Agent (SQLi Injection / Scanning)"; 
flow:established,to_server; content:"User-Agent|3a 20|testitest"; 
http_header; fast_pattern; 
reference:url,en.wikipedia.org/wiki/SQL_injection; 
classtype:web-application-attack; sid:2023351; rev:1; 
metadata:attack_target SQL_Server, created_at 2016_10_19, deployment 
Datacenter, performance_impact Low, signature_severity Major, updated_at 
2020_07_31;)


I tested on snort 2.9.9.0 and 2.9.19.


Thanks.

-- 
Fatih USTA

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.