Re: alert_json logger - not working

Lee Clemens via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <DM6PR20MB272992CE2C415C865E7DD83DA61F9@DM6PR20MB2729.namprd20.prod.outlook.com>
For comparison, /var/log/snort is 7700 and owned by snort:snort in my setup.


From: Snort-users <[email protected]> On Behalf Of Michael Heard via Snort-users
Sent: Wednesday, March 30, 2022 12:08 AM
To: [email protected]
Subject: [Snort-users] alert_json logger - not working

***CAUTION: EXTERNAL EMAIL - Think before you click! ***
Hello,

I have recently installed Snort3 on Centos Stream 8, using the instructions provided by Snort 3 on the CentOS 8 Stream document (Snort_3_GA_on_CentOS8_Stream.pdf). I believe I successfully completed the steps of sections 7.5 (Configuring alert_json Logger), but the installation doesn't appear to work. A file is created with the name "alert_json.txt, but it doesn't contain any contents. Is something missing in my configuration? Can someone provide some insight into what might be causing this problem?

See attachments:

  1.  snort.lua
  2.  snort_default.lua
  3.  Results of running a test against a pcap.
Here's what the snort log folder looks like:

[root@localhost snort]# cd /var/log/snort/
[root@localhost snort]# ls -la
total 4
drws-----T.  2 snort snort   50 Mar 29 21:04 .
drwxr-xr-x. 10 root  root  4096 Mar 27 03:49 ..
-rw-r--r--   1 root  root     0 Mar 29 21:04 alert_fast.txt
-rw-r--r--   1 root  root     0 Mar 29 21:04 alert_json.txt


Thanks

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.