Re: Problem with snort 3
"Oleksii Shumeiko -X \(oshumeik - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Hi. As far as I know, the rule message always appears in double-quotes. But, you can configure the logger to not print the message. The following command will give you a list of available loggers: ./snort --list-modules | grep alert For example, alert_csv can be configured which info about the event will be logged: ./snort --help-module alert_csv Have a nice day ahead! On 20 Jun 2022, at 23:46, Hakar Shamal via Snort-users <[email protected]<mailto:[email protected]>> wrote: Hello, I've configured snort 3 and i've enabled logging to an output file but the logs appear like the following. Is there any way to remove the " " around the description from the snort config file? <38>Jun 5 17:16:39 snort snort: [1:1000001:1] "ICMP connection test" {ICMP} 172.30.0.3 -> 172.100.0.42 Thank you so much, Regards, _______________________________________________ Snort-users mailing list [email protected]<mailto:[email protected]> Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette