Fwd: Snort 2.9.x ruletype logging output question
Dorian ROSSE via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <DB6PR08MB285533E7EAE428EF70D4CF3FDA269@DB6PR08MB2855.eurprd08.prod.outlook.com> |
Hello,
You forbid to log to a program with underscore then the program who is use as a log :
For example with syslog :
log_syslog
Finally if unified and syslog are use as a logger your rule is typed like these :
output unified2: filename snort_unified.log, limit 128
ruletype my_alert {
type alert
output unified2 log_unified2 : filename snort_unified.log, limit 128
output alert_syslog log_syslog : log_auth log_alert
}
my_alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SPECIFIC_APPS User Agent (SQLi Injection / Scanning)"; flow:established,to_server; content:"User-Agent|3a 20|testitest"; http_header; fast_pattern; reference:url,en.wikipedia.org/wiki/SQL_injection<http://en.wikipedia.org/wiki/SQL_injection>; classtype:web-application-attack; sid:2023351; rev:1; metadata:attack_target SQL_Server, created_at 2016_10_19, deployment Datacenter, performance_impact Low, signature_severity Major, updated_at 2020_07_31;)
I hope success your problem,
Regards.
Dorian Rosse.
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette