Re: Snort3 logger of action type 'alert' and 'log'
"Andrii Serbeniuk -X \(aserbeni - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]> Wed, 23 Oct 2024 09:58:29 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <SJ0PR11MB520022D97BC8A2713EC72EA8C54D2@SJ0PR11MB5200.namprd11.prod.outlook.com> |
--===============0745500618751042493== Content-Language: en-GB Content-Type: multipart/alternative; boundary="_000_SJ0PR11MB520022D97BC8A2713EC72EA8C54D2SJ0PR11MB5200namp_" --_000_SJ0PR11MB520022D97BC8A2713EC72EA8C54D2SJ0PR11MB5200namp_ Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable Hi Brian, Right, rule actions have priorities over one another if multiple rules matc= h at the same time, and if a higher priority action is triggered then lower= priority ones won=92t be executed, by default. Config option responsible for this is =93event_queue.process_all_events=94,= which is false by default. By setting it to true, all rule actions will be= applied on the event. Config option responsible for the actions priority order is =93alerts.order= =94, the default order is =93pass reject block react drop rewrite alert log= file_id=94. Regards, Andrii From: Brian Jameson <[email protected]> Date: Wednesday, 23 October 2024 at 11:46 To: Andrii Serbeniuk -X (aserbeni - SOFTSERVE INC at Cisco) <aserbeni@cisco= .com>, [email protected] <[email protected]> Subject: Re: [Snort-users] Snort3 logger of action type 'alert' and 'log' Andrii, Thanks for the snort3_extra link. That will be good at some point i= n the future, but a bit too much at the moment being a newbie to snort3 and .lua files. In my original post I asked if my assumption that if an 'alert' rule triggered then a 'log' rule would not be executed. This seems to be how a 'pass' rule works with 'alerts'. Can you help with this? regards, Brian On 21/10/2024 08:55, Andrii Serbeniuk -X (aserbeni - SOFTSERVE INC at Cisco) wrote: > Hi Brian, > > Existing snort loggers don=92t have functionality to separate entries by > event type, if you=92d like to have this behavior with any of them you > could try logging all the events into a single file and managing it with > some external script. > > Alternatively, you could take a look at this lua logger example from > snort3_extra: https://github.com/snort3/snort3_extra/blob/master/src/ > loggers/alert_lua/alert.lua <https://github.com/snort3/snort3_extra/ > blob/master/src/loggers/alert_lua/alert.lua> > With this you can implement your own steps during eventing, including > file separation by event type. > > Hope this can be of use. > > Regards, > > Andrii > > *From: *Snort-users <[email protected]> on behalf of > Brian Jameson via Snort-users <[email protected]> > *Date: *Thursday, 17 October 2024 at 17:17 > *To: *[email protected] <[email protected]> > *Subject: *[Snort-users] Snort3 logger of action type 'alert' and 'log' > > I have returned to snort after several years and am trying to get to > know snort3. I have 'alerts' being logged to alert_csv, which goes on to > record the data in MySQL. But I would also like to use an action type of > 'log' for some rules. This is on the assumption that rules that trigger > an alert will not go onto trigger a log. I would like to output the log > alerts using something like the -A cmg but preferably to a file. Any > suggestions on how to output two log types to seperate 'alert' and 'log' > types? I assume this is done in snort.lua but where and how. > > > _______________________________________________ > Snort-users mailing list > [email protected] > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users <https:// > lists.snort.org/mailman/listinfo/snort-users> > > To unsubscribe, send an email to: > [email protected] > > Please visit http://blog.snort.org <http://blog.snort.org> to stay > current on all the latest Snort news! > > Please follow these rules: https://snort.org/faq/what-is-the-mailing- > list-etiquette <https://snort.org/faq/what-is-the-mailing-list-etiquette> > --_000_SJ0PR11MB520022D97BC8A2713EC72EA8C54D2SJ0PR11MB5200namp_ Content-Type: text/html; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable <html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc= hemas-microsoft-com:office:word" xmlns:m=3D"http://schemas.microsoft.com/of= fice/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-html40"> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1= 252"> <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)"> <style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Aptos; panose-1:2 11 0 4 2 2 2 2 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0cm; font-size:12.0pt; font-family:"Aptos",sans-serif;} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt; mso-ligatures:none;} @page WordSection1 {size:612.0pt 792.0pt; margin:72.0pt 72.0pt 72.0pt 72.0pt;} div.WordSection1 {page:WordSection1;} --></style> </head> <body lang=3D"en-UA" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea= k-word"> <div class=3D"WordSection1"> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US">Hi Brian,<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US">Right, rule actions have priorities over one another= if multiple rules match at the same time, and if a higher priority action = is triggered then lower priority ones won=92t be executed, by default.<br> Config option responsible for this is =93event_queue.process_all_events=94,= which is false by default. By setting it to true, all rule actions will be= applied on the event.<br> Config option responsible for the actions priority order is =93alerts.order= =94, the default order is =93pass reject block react drop rewrite alert log= file_id=94.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US">Regards,<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f= areast-language:EN-US">Andrii<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language= :EN-US"><o:p> </o:p></span></p> <div id=3D"mail-editor-reference-message-container"> <div> <div> <div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm = 0cm 0cm"> <p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><b><span style=3D"col= or:black">From: </span></b><span style=3D"color:black">Brian Jameson <[email protected]= k><br> <b>Date: </b>Wednesday, 23 October 2024 at 11:46<br> <b>To: </b>Andrii Serbeniuk -X (aserbeni - SOFTSERVE INC at Cisco) <aser= [email protected]>, [email protected] <[email protected]= .org><br> <b>Subject: </b>Re: [Snort-users] Snort3 logger of action type 'alert' and = 'log'<o:p></o:p></span></p> </div> <div> <p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span style=3D"font-s= ize:11.0pt">Andrii,<br> Thanks for the snort3_extra link= . That will be good at some point in <br> the future, but a bit too much at the moment being a newbie to snort3 <br> and .lua files.<br> In my original post I asked if my assumption that if an 'alert' rule <br> triggered then a 'log' rule would not be executed. This seems to be how <br= > a 'pass' rule works with 'alerts'. Can you help with this?<br> regards,<br> Brian<br> <br> <br> On 21/10/2024 08:55, Andrii Serbeniuk -X (aserbeni - SOFTSERVE INC at <br> Cisco) wrote:<br> > Hi Brian,<br> > <br> > Existing snort loggers don=92t have functionality to separate entries = by <br> > event type, if you=92d like to have this behavior with any of them you= <br> > could try logging all the events into a single file and managing it wi= th <br> > some external script.<br> > <br> > Alternatively, you could take a look at this lua logger example from <= br> > snort3_extra: </span><a href=3D"https://github.com/snort3/snort3_extra= /blob/master/src/"><span style=3D"font-size:11.0pt">https://github.com/snor= t3/snort3_extra/blob/master/src/</span></a><span style=3D"font-size:11.0pt"= > <br> > loggers/alert_lua/alert.lua <https://github.com/snort3/snort3_extra= / <br> > blob/master/src/loggers/alert_lua/alert.lua><br> > With this you can implement your own steps during eventing, including = <br> > file separation by event type.<br> > <br> > Hope this can be of use.<br> > <br> > Regards,<br> > <br> > Andrii<br> > <br> > *From: *Snort-users <[email protected]> on beh= alf of <br> > Brian Jameson via Snort-users <[email protected]><br> > *Date: *Thursday, 17 October 2024 at 17:17<br> > *To: *[email protected] <[email protected]><= br> > *Subject: *[Snort-users] Snort3 logger of action type 'alert' and 'log= '<br> > <br> > I have returned to snort after several years and am trying to get to<b= r> > know snort3. I have 'alerts' being logged to alert_csv, which goes on = to<br> > record the data in MySQL. But I would also like to use an action type = of<br> > 'log' for some rules. This is on the assumption that rules that trigge= r<br> > an alert will not go onto trigger a log. I would like to output the lo= g<br> > alerts using something like the -A cmg but preferably to a file. Any<b= r> > suggestions on how to output two log types to seperate 'alert' and 'lo= g'<br> > types? I assume this is done in snort.lua but where and how.<br> > <br> > <br> > _______________________________________________<br> > Snort-users mailing list<br> > [email protected]<br> > Go to this URL to change user options or unsubscribe:<br> > </span><a href=3D"https://lists.snort.org/mailman/listinfo/snort-users= "><span style=3D"font-size:11.0pt">https://lists.snort.org/mailman/listinfo= /snort-users</span></a><span style=3D"font-size:11.0pt"> <https:// <br> > lists.snort.org/mailman/listinfo/snort-users><br> > <br> > To unsubscribe, send = an email to:<br> > snort-users-leave@lis= ts.snort.org<br> > <br> > Please visit </span><a href=3D"http://blog.snort.org"><span style=3D"f= ont-size:11.0pt">http://blog.snort.org</span></a><span style=3D"font-size:1= 1.0pt"> <</span><a href=3D"http://blog.snort.org"><span style=3D"font-si= ze:11.0pt">http://blog.snort.org</span></a><span style=3D"font-size:11.0pt"= >> to stay <br> > current on all the latest Snort news!<br> > <br> > Please follow these rules: </span><a href=3D"https://snort.org/faq/wha= t-is-the-mailing-"><span style=3D"font-size:11.0pt">https://snort.org/faq/w= hat-is-the-mailing-</span></a><span style=3D"font-size:11.0pt"> <br> > list-etiquette <</span><a href=3D"https://snort.org/faq/what-is-the= -mailing-list-etiquette"><span style=3D"font-size:11.0pt">https://snort.org= /faq/what-is-the-mailing-list-etiquette</span></a><span style=3D"font-size:= 11.0pt">><br> > <o:p></o:p></span></p> </div> </div> </div> </div> </div> </body> </html> --_000_SJ0PR11MB520022D97BC8A2713EC72EA8C54D2SJ0PR11MB5200namp_-- --===============0745500618751042493== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette --===============0745500618751042493==--