Snort3 logger of action type 'alert' and 'log'

Brian Jameson via Snort-users <[email protected]> Wed, 16 Oct 2024 12:15:29 +0100
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
I have returned to snort after several years and am trying to get to 
know snort3. I have 'alerts' being logged to alert_csv, which goes on to 
record the data in MySQL. But I would also like to use an action type of 
'log' for some rules. This is on the assumption that rules that trigger 
an alert will not go onto trigger a log. I would like to output the log 
alerts using something like the -A cmg but preferably to a file. Any 
suggestions on how to output two log types to seperate 'alert' and 'log' 
types? I assume this is done in snort.lua but where and how.


_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette