Re: Snort3 logger of action type 'alert' and 'log'
"Andrii Serbeniuk -X \(aserbeni - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]> Mon, 21 Oct 2024 07:55:10 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CO1PR11MB5186E4B769F0697346C15422C5432@CO1PR11MB5186.namprd11.prod.outlook.com> |
--===============8228159708448858640== Content-Language: en-GB Content-Type: multipart/alternative; boundary="_000_CO1PR11MB5186E4B769F0697346C15422C5432CO1PR11MB5186namp_" --_000_CO1PR11MB5186E4B769F0697346C15422C5432CO1PR11MB5186namp_ Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable Hi Brian, Existing snort loggers don=92t have functionality to separate entries by ev= ent type, if you=92d like to have this behavior with any of them you could = try logging all the events into a single file and managing it with some ext= ernal script. Alternatively, you could take a look at this lua logger example from snort3= _extra: https://github.com/snort3/snort3_extra/blob/master/src/loggers/aler= t_lua/alert.lua With this you can implement your own steps during eventing, including file = separation by event type. Hope this can be of use. Regards, Andrii From: Snort-users <[email protected]> on behalf of Brian = Jameson via Snort-users <[email protected]> Date: Thursday, 17 October 2024 at 17:17 To: [email protected] <[email protected]> Subject: [Snort-users] Snort3 logger of action type 'alert' and 'log' I have returned to snort after several years and am trying to get to know snort3. I have 'alerts' being logged to alert_csv, which goes on to record the data in MySQL. But I would also like to use an action type of 'log' for some rules. This is on the assumption that rules that trigger an alert will not go onto trigger a log. I would like to output the log alerts using something like the -A cmg but preferably to a file. Any suggestions on how to output two log types to seperate 'alert' and 'log' types? I assume this is done in snort.lua but where and how. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort = news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-e= tiquette --_000_CO1PR11MB5186E4B769F0697346C15422C5432CO1PR11MB5186namp_ Content-Type: text/html; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable <html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc= hemas-microsoft-com:office:word" xmlns:m=3D"http://schemas.microsoft.com/of= fice/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-html40"> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1= 252"> <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)"> <style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Aptos; panose-1:2 11 0 4 2 2 2 2 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0cm; font-size:12.0pt; font-family:"Aptos",sans-serif;} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} span.EmailStyle19 {mso-style-type:personal-reply; font-family:"Aptos",sans-serif; color:windowtext;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt; mso-ligatures:none;} @page WordSection1 {size:612.0pt 792.0pt; margin:72.0pt 72.0pt 72.0pt 72.0pt;} div.WordSection1 {page:WordSection1;} --></style> </head> <body lang=3D"en-UA" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea= k-word"> <div class=3D"WordSection1"> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US">Hi Brian,<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US">Existing snort loggers don=92t have functionality to= separate entries by event type, if you=92d like to have this behavior with= any of them you could try logging all the events into a single file and managing it with some external script.<o:p><= /o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US">Alternatively, you could take a look at this lua log= ger example from snort3_extra: <a href=3D"https://github.com/snort3/snort3_extra/blob/master/src/loggers/a= lert_lua/alert.lua"> https://github.com/snort3/snort3_extra/blob/master/src/loggers/alert_lua/al= ert.lua</a><br> With this you can implement your own steps during eventing, including file = separation by event type.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US">Hope this can be of use.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US">Regards,<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US">Andrii<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language= :EN-US"><o:p> </o:p></span></p> <div id=3D"mail-editor-reference-message-container"> <div> <div> <div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm = 0cm 0cm"> <p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><b><span style=3D"col= or:black">From: </span></b><span style=3D"color:black">Snort-users <snort-users-bounces@= lists.snort.org> on behalf of Brian Jameson via Snort-users <snort-us= [email protected]><br> <b>Date: </b>Thursday, 17 October 2024 at 17:17<br> <b>To: </b>[email protected] <[email protected]><= br> <b>Subject: </b>[Snort-users] Snort3 logger of action type 'alert' and 'log= '<o:p></o:p></span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt">I have returned to = snort after several years and am trying to get to <br> know snort3. I have 'alerts' being logged to alert_csv, which goes on to <b= r> record the data in MySQL. But I would also like to use an action type of <b= r> 'log' for some rules. This is on the assumption that rules that trigger <br= > an alert will not go onto trigger a log. I would like to output the log <br= > alerts using something like the -A cmg but preferably to a file. Any <br> suggestions on how to output two log types to seperate 'alert' and 'log' <b= r> types? I assume this is done in snort.lua but where and how.<br> <br> <br> _______________________________________________<br> Snort-users mailing list<br> [email protected]<br> Go to this URL to change user options or unsubscribe:<br> <a href=3D"https://lists.snort.org/mailman/listinfo/snort-users">https://li= sts.snort.org/mailman/listinfo/snort-users</a><br> <br> To unsubscribe, send an email to= :<br> [email protected]= g<br> <br> Please visit <a href=3D"http://blog.snort.org">http://blog.snort.org</a> to= stay current on all the latest Snort news!<br> <br> Please follow these rules: <a href=3D"https://snort.org/faq/what-is-the-mai= ling-list-etiquette"> https://snort.org/faq/what-is-the-mailing-list-etiquette</a><o:p></o:p></sp= an></p> </div> </div> </div> </div> </div> </body> </html> --_000_CO1PR11MB5186E4B769F0697346C15422C5432CO1PR11MB5186namp_-- --===============8228159708448858640== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette --===============8228159708448858640==--