Fwd: Snort 2.9.x ruletype logging output question
Fatih USTA via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Hi First off all i didn't get your answer to my email box, so I copied your answer to here from the web. I'm not asking signature specific question. I'm asking configuration question. Normally signature matches traffic and I saw at the log, so there is no problem here. Snort doesn't log for the traffic when I want to use different rule action for multiple logging output. I think, there is a bug here or what am I missing for correct configuration? I'm fallowing this documentation. http://manual-snort-org.s3-website-us-east-1.amazonaws.com/node29.html#SECTION00421000000000000000 Thanks. ----- Dorian ROSSE dorianbrice at hotmail.fr Wed Jan 26 12:06:40 UTC 2022 Previous message (by thread): [Snort-users] Snort 2.9.x ruletype logging output question Next message (by thread): [Snort-users] snort3: correct and effective number of packet threads Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] Hello, You should subscribe to snort sig and ask your question to snort sig, This is a rule questions so you should ask to there, Regards. Dorian Rosse. -------------- next part -------------- An HTML attachment was scrubbed... URL: <https://lists.snort.org/pipermail/snort-users/attachments/20220126/e74da81b/attachment.htm> -------- Forwarded Message -------- Subject: Snort 2.9.x ruletype logging output question Date: Tue, 25 Jan 2022 12:06:29 +0300 From: Fatih USTA <[email protected]> To: [email protected] Hi I'm trying to use "ruletype" to multiple logging output for specific rules. I defined a "ruletype" and I used in the rule. I can't see any output. Are there any idea? output unified2: filename snort_unified.log, limit 128 ruletype my_alert { type alert output unified2: filename snort_unified.log, limit 128 output alert_syslog: log_auth log_alert } my_alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SPECIFIC_APPS User Agent (SQLi Injection / Scanning)"; flow:established,to_server; content:"User-Agent|3a 20|testitest"; http_header; fast_pattern; reference:url,en.wikipedia.org/wiki/SQL_injection; classtype:web-application-attack; sid:2023351; rev:1; metadata:attack_target SQL_Server, created_at 2016_10_19, deployment Datacenter, performance_impact Low, signature_severity Major, updated_at 2020_07_31;) I tested on snort 2.9.9.0 and 2.9.19. Thanks. -- Fatih USTA _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette