Re: Fwd: Snort 2.9.x ruletype logging output question
Fatih USTA via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
thank you for your help. I will subscribe to snort-devel list. Fatih USTA On 1.02.2022 18:37, Dorian ROSSE wrote: > I don't understand how to do more, > > subscribe to snort devel or snort sig for publish your problem they > will go more far instead the help of snort user, > > I hope your success, > > Regards. > > > Dorian Rosse. > ------------------------------------------------------------------------ > *From:* Fatih USTA <[email protected]> > *Sent:* Tuesday, February 1, 2022 4:33:58 PM > *To:* Dorian ROSSE <[email protected]>; > [email protected] <[email protected]> > *Subject:* Re: [Snort-users] Fwd: Snort 2.9.x ruletype logging output > question > > yes, I tried. > > Regards. > > Fatih USTA > On 1.02.2022 18:28, Dorian ROSSE wrote: >> Have you tried this : >> >> snort -A console -D -d -i eth2 -u snort -g snort -c /etc/snort.conf >> -l /var/log/snort >> >> I hope your success, >> >> Regards. >> >> >> Dorian Rosse. >> ------------------------------------------------------------------------ >> *From:* Fatih USTA <[email protected]> <mailto:[email protected]> >> *Sent:* Tuesday, February 1, 2022 4:22:28 PM >> *To:* Dorian ROSSE <[email protected]> >> <mailto:[email protected]>; [email protected] >> <mailto:[email protected]> <[email protected]> >> <mailto:[email protected]> >> *Subject:* Re: [Snort-users] Fwd: Snort 2.9.x ruletype logging output >> question >> >> I tried but nothing changed. I think, option '-A' is not related of >> my issue. >> >> -A Set alert mode: fast, full, console, test or none >> (alert file alerts only) >> "unsock" enables UNIX socket logging (experimental). >> >> Fatih USTA >> On 1.02.2022 18:14, Dorian ROSSE wrote: >>> You forgot -A or lowercase -a for alert, >>> >>> I hope your success, >>> >>> Regards. >>> >>> >>> Dorian Rosse. >>> ------------------------------------------------------------------------ >>> *From:* Fatih USTA <[email protected]> >>> <mailto:[email protected]> >>> *Sent:* Tuesday, February 1, 2022 4:08:55 PM >>> *To:* Dorian ROSSE <[email protected]> >>> <mailto:[email protected]>; [email protected] >>> <mailto:[email protected]> <[email protected]> >>> <mailto:[email protected]> >>> *Subject:* Re: [Snort-users] Fwd: Snort 2.9.x ruletype logging >>> output question >>> >>> >>> These are my command line options. >>> >>> -D -d -i eth2 -u snort -g snort -c /etc/snort.conf -l /var/log/snort >>> >>> Permission of directory >>> drwxr-xr-x 2 snort snort 4096 Şub 1 17:52 /var/log/snort >>> >>> Permission of file >>> >>> -rw------- 1 snort snort 0 Şub 1 17:52 snort_unified.log.1643727125 >>> >>> -c <rules> Use Rules File <rules> >>> -d Dump the Application Layer >>> -D Run Snort in background (daemon) mode >>> -g <gname> Run snort gid as <gname> group (or gid) after >>> initialization >>> -i <if> Listen on interface <if> >>> -l <ld> Log to directory <ld> >>> -L <file> Log to this tcpdump file >>> -u <uname> Run snort uid as <uname> user (or uid) after >>> initialization >>> >>> Regards >>> >>> Fatih USTA >>> On 1.02.2022 17:59, Dorian ROSSE wrote: >>>> This isn't fully the same lines of command, >>>> >>>> Do you had -l option or uppercase -L option (I don't remember if >>>> this is a L letter lowercase or uppercase) for create log when you >>>> launch snort ? >>>> >>>> I hope your success, >>>> >>>> Regards. >>>> >>>> >>>> Dorian Rosse. >>>> ------------------------------------------------------------------------ >>>> *From:* Fatih USTA <[email protected]> >>>> <mailto:[email protected]> >>>> *Sent:* Tuesday, February 1, 2022 3:51:26 PM >>>> *To:* Dorian ROSSE <[email protected]> >>>> <mailto:[email protected]>; [email protected] >>>> <mailto:[email protected]> <[email protected]> >>>> <mailto:[email protected]> >>>> *Subject:* Re: [Snort-users] Fwd: Snort 2.9.x ruletype logging >>>> output question >>>> >>>> I already tried this config. (I think, this is almost same as my >>>> first config) Service starting without any error. But I can't see >>>> any alert of signature. >>>> >>>> >>>> Fatih USTA >>>> On 1.02.2022 17:13, Dorian ROSSE wrote: >>>>> Try with this : >>>>> >>>>> ruletype my_alert { >>>>> type alert >>>>> output log_unified2 : filename snort_unified.log, limit 128 >>>>> output alert_syslog : LOG_AUTH LOG_ALERT >>>>> } >>>>> >>>>> my_alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS >>>>> $HTTP_PORTS(msg:"ET WEB_SPECIFIC_APPS User Agent (SQLi Injection >>>>> /Scanning)"; flow:established,to_server; >>>>> content:"User-Agent|3a20|testitest"; http_header; >>>>> fast_pattern;reference:url,en.wikipedia.org/wiki/SQL_injection >>>>> <http://en.wikipedia.org/wiki/SQL_injection>;classtype:web-application-attack; >>>>> sid:2023351; rev:1;metadata:attack_target SQL_Server, created_at >>>>> 2016_10_19,deployment Datacenter, performance_impact Low, >>>>> signature_severityMajor, updated_at 2020_07_31;) >>>>> >>>>> I hope your success, >>>>> >>>>> Regards. >>>>> >>>>> >>>>> Dorian Rosse. >>>>> ------------------------------------------------------------------------ >>>>> *From:* Fatih USTA <[email protected]> >>>>> <mailto:[email protected]> >>>>> *Sent:* Tuesday, February 1, 2022 2:59:36 PM >>>>> *To:* Dorian ROSSE <[email protected]> >>>>> <mailto:[email protected]>; [email protected] >>>>> <mailto:[email protected]> <[email protected]> >>>>> <mailto:[email protected]> >>>>> *Subject:* Re: [Snort-users] Fwd: Snort 2.9.x ruletype logging >>>>> output question >>>>> >>>>> Hello, >>>>> >>>>> I copied and pasted into my config. But didn't worked. >>>>> >>>>> >>>>> Unknown output plugin "unified2 log_unified2" >>>>> >>>>> Unknown output plugin "alert_syslog log_syslog" >>>>> >>>>> Fatal Error, Quitting.. >>>>> >>>>> >>>>> Output plugin is plugged in... >>>>> ------------------------------------------------- >>>>> Keyword | Output @ >>>>> ------------------------------------------------- >>>>> alert_syslog : 0x80ae428 >>>>> log_tcpdump : 0x80b3d88 >>>>> alert_fast : 0x80ad590 >>>>> alert_full : 0x80adde4 >>>>> alert_unixsock: 0x80b2718 >>>>> alert_CSV : 0x80b2c24 >>>>> log_null : 0x80b3d18 >>>>> log_unified2 : 0x80b7496 >>>>> alert_unified2: 0x80b738a >>>>> unified2 : 0x80b46dc >>>>> log_ascii : 0x80b7a30 >>>>> alert_sf_socket: 0x80b880c >>>>> alert_sf_socket_sid: 0x80b8b83 >>>>> alert_test : 0x80b92e8 >>>>> alert_fwsam : 0x80af4c4 >>>>> >>>>> >>>>> Fatih USTA >>>>> On 1.02.2022 15:20, Dorian ROSSE via Snort-users wrote: >>>>>> Hello, >>>>>> >>>>>> >>>>>> You forbid to log to a program with underscore then the program >>>>>> who is use as a log : >>>>>> >>>>>> For example with syslog : >>>>>> >>>>>> log_syslog >>>>>> >>>>>> Finally if unified and syslog are use as a logger your rule is >>>>>> typed like these : >>>>>> >>>>>> output unified2: filename snort_unified.log, limit 128 >>>>>> >>>>>> ruletype my_alert { >>>>>> type alert >>>>>> output unified2 log_unified2 : filename snort_unified.log, limit 128 >>>>>> output alert_syslog log_syslog : log_auth log_alert >>>>>> } >>>>>> >>>>>> my_alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS >>>>>> $HTTP_PORTS(msg:"ET WEB_SPECIFIC_APPS User Agent (SQLi Injection >>>>>> /Scanning)"; flow:established,to_server; >>>>>> content:"User-Agent|3a20|testitest"; http_header; >>>>>> fast_pattern;reference:url,en.wikipedia.org/wiki/SQL_injection >>>>>> <http://en.wikipedia.org/wiki/SQL_injection>;classtype:web-application-attack; >>>>>> sid:2023351; rev:1;metadata:attack_target SQL_Server, created_at >>>>>> 2016_10_19,deployment Datacenter, performance_impact Low, >>>>>> signature_severityMajor, updated_at 2020_07_31;) >>>>>> >>>>>> I hope success your problem, >>>>>> >>>>>> Regards. >>>>>> >>>>>> >>>>>> Dorian Rosse. >>>>>> >>>>>> _______________________________________________ >>>>>> Snort-users mailing list >>>>>> [email protected] <mailto:[email protected]> >>>>>> Go to this URL to change user options or unsubscribe: >>>>>> https://lists.snort.org/mailman/listinfo/snort-users <https://lists.snort.org/mailman/listinfo/snort-users> >>>>>> >>>>>> To unsubscribe, send an email to: >>>>>> [email protected] <mailto:[email protected]> >>>>>> >>>>>> Please visithttp://blog.snort.org <http://blog.snort.org> to stay current on all the latest Snort news! >>>>>> >>>>>> Please follow these rules:https://snort.org/faq/what-is-the-mailing-list-etiquette <https://snort.org/faq/what-is-the-mailing-list-etiquette> _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette