Fwd: Snort 2.9.x ruletype logging output question

Dorian ROSSE via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <DB6PR08MB285533E7EAE428EF70D4CF3FDA269@DB6PR08MB2855.eurprd08.prod.outlook.com>
Hello,


You forbid to log to a program with underscore then the program who is use as a log :

For example with syslog :

log_syslog

Finally if unified and syslog are use as a logger your rule is typed like these :

output unified2: filename snort_unified.log, limit 128

ruletype my_alert {
type alert
output unified2 log_unified2 : filename snort_unified.log, limit 128
output alert_syslog log_syslog : log_auth log_alert
}

my_alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SPECIFIC_APPS User Agent (SQLi Injection / Scanning)"; flow:established,to_server; content:"User-Agent|3a 20|testitest"; http_header; fast_pattern; reference:url,en.wikipedia.org/wiki/SQL_injection<http://en.wikipedia.org/wiki/SQL_injection>; classtype:web-application-attack; sid:2023351; rev:1; metadata:attack_target SQL_Server, created_at 2016_10_19, deployment Datacenter, performance_impact Low, signature_severity Major, updated_at 2020_07_31;)

I hope success your problem,

Regards.


Dorian Rosse.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.