Re: Snort3 logger of action type 'alert' and 'log'

"Andrii Serbeniuk -X \(aserbeni - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]> Mon, 21 Oct 2024 07:55:10 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CO1PR11MB5186E4B769F0697346C15422C5432@CO1PR11MB5186.namprd11.prod.outlook.com>
--===============8228159708448858640==
Content-Language: en-GB
Content-Type: multipart/alternative;
	boundary="_000_CO1PR11MB5186E4B769F0697346C15422C5432CO1PR11MB5186namp_"

--_000_CO1PR11MB5186E4B769F0697346C15422C5432CO1PR11MB5186namp_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Hi Brian,

Existing snort loggers don=92t have functionality to separate entries by ev=
ent type, if you=92d like to have this behavior with any of them you could =
try logging all the events into a single file and managing it with some ext=
ernal script.
Alternatively, you could take a look at this lua logger example from snort3=
_extra: https://github.com/snort3/snort3_extra/blob/master/src/loggers/aler=
t_lua/alert.lua
With this you can implement your own steps during eventing, including file =
separation by event type.

Hope this can be of use.

Regards,
Andrii

From: Snort-users <[email protected]> on behalf of Brian =
Jameson via Snort-users <[email protected]>
Date: Thursday, 17 October 2024 at 17:17
To: [email protected] <[email protected]>
Subject: [Snort-users] Snort3 logger of action type 'alert' and 'log'
I have returned to snort after several years and am trying to get to
know snort3. I have 'alerts' being logged to alert_csv, which goes on to
record the data in MySQL. But I would also like to use an action type of
'log' for some rules. This is on the assumption that rules that trigger
an alert will not go onto trigger a log. I would like to output the log
alerts using something like the -A cmg but preferably to a file. Any
suggestions on how to output two log types to seperate 'alert' and 'log'
types? I assume this is done in snort.lua but where and how.


_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

        To unsubscribe, send an email to:
        [email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort =
news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-e=
tiquette

--_000_CO1PR11MB5186E4B769F0697346C15422C5432CO1PR11MB5186namp_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc=
hemas-microsoft-com:office:word" xmlns:m=3D"http://schemas.microsoft.com/of=
fice/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Aptos;
	panose-1:2 11 0 4 2 2 2 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	font-size:12.0pt;
	font-family:"Aptos",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
span.EmailStyle19
	{mso-style-type:personal-reply;
	font-family:"Aptos",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;
	mso-ligatures:none;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style>
</head>
<body lang=3D"en-UA" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea=
k-word">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US">Hi Brian,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US">Existing snort loggers don=92t have functionality to=
 separate entries by event type, if you=92d like to have this behavior with=
 any of them you could try logging all the
 events into a single file and managing it with some external script.<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US">Alternatively, you could take a look at this lua log=
ger example from snort3_extra:
<a href=3D"https://github.com/snort3/snort3_extra/blob/master/src/loggers/a=
lert_lua/alert.lua">
https://github.com/snort3/snort3_extra/blob/master/src/loggers/alert_lua/al=
ert.lua</a><br>
With this you can implement your own steps during eventing, including file =
separation by event type.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US">Hope this can be of use.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US">Regards,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US">Andrii<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:EN-US"><o:p>&nbsp;</o:p></span></p>
<div id=3D"mail-editor-reference-message-container">
<div>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><b><span style=3D"col=
or:black">From:
</span></b><span style=3D"color:black">Snort-users &lt;snort-users-bounces@=
lists.snort.org&gt; on behalf of Brian Jameson via Snort-users &lt;snort-us=
[email protected]&gt;<br>
<b>Date: </b>Thursday, 17 October 2024 at 17:17<br>
<b>To: </b>[email protected] &lt;[email protected]&gt;<=
br>
<b>Subject: </b>[Snort-users] Snort3 logger of action type 'alert' and 'log=
'<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt">I have returned to =
snort after several years and am trying to get to
<br>
know snort3. I have 'alerts' being logged to alert_csv, which goes on to <b=
r>
record the data in MySQL. But I would also like to use an action type of <b=
r>
'log' for some rules. This is on the assumption that rules that trigger <br=
>
an alert will not go onto trigger a log. I would like to output the log <br=
>
alerts using something like the -A cmg but preferably to a file. Any <br>
suggestions on how to output two log types to seperate 'alert' and 'log' <b=
r>
types? I assume this is done in snort.lua but where and how.<br>
<br>
<br>
_______________________________________________<br>
Snort-users mailing list<br>
[email protected]<br>
Go to this URL to change user options or unsubscribe:<br>
<a href=3D"https://lists.snort.org/mailman/listinfo/snort-users">https://li=
sts.snort.org/mailman/listinfo/snort-users</a><br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To unsubscribe, send an email to=
:<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; [email protected]=
g<br>
<br>
Please visit <a href=3D"http://blog.snort.org">http://blog.snort.org</a> to=
 stay current on all the latest Snort news!<br>
<br>
Please follow these rules: <a href=3D"https://snort.org/faq/what-is-the-mai=
ling-list-etiquette">
https://snort.org/faq/what-is-the-mailing-list-etiquette</a><o:p></o:p></sp=
an></p>
</div>
</div>
</div>
</div>
</div>
</body>
</html>

--_000_CO1PR11MB5186E4B769F0697346C15422C5432CO1PR11MB5186namp_--

--===============8228159708448858640==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============8228159708448858640==--