Re: Snort3 logger of action type 'alert' and 'log'

"Andrii Serbeniuk -X \(aserbeni - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]> Wed, 23 Oct 2024 09:58:29 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <SJ0PR11MB520022D97BC8A2713EC72EA8C54D2@SJ0PR11MB5200.namprd11.prod.outlook.com>
--===============0745500618751042493==
Content-Language: en-GB
Content-Type: multipart/alternative;
	boundary="_000_SJ0PR11MB520022D97BC8A2713EC72EA8C54D2SJ0PR11MB5200namp_"

--_000_SJ0PR11MB520022D97BC8A2713EC72EA8C54D2SJ0PR11MB5200namp_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Hi Brian,

Right, rule actions have priorities over one another if multiple rules matc=
h at the same time, and if a higher priority action is triggered then lower=
 priority ones won=92t be executed, by default.
Config option responsible for this is =93event_queue.process_all_events=94,=
 which is false by default. By setting it to true, all rule actions will be=
 applied on the event.
Config option responsible for the actions priority order is =93alerts.order=
=94, the default order is =93pass reject block react drop rewrite alert log=
 file_id=94.

Regards,
Andrii

From: Brian Jameson <[email protected]>
Date: Wednesday, 23 October 2024 at 11:46
To: Andrii Serbeniuk -X (aserbeni - SOFTSERVE INC at Cisco) <aserbeni@cisco=
.com>, [email protected] <[email protected]>
Subject: Re: [Snort-users] Snort3 logger of action type 'alert' and 'log'
Andrii,
        Thanks for the snort3_extra link. That will be good at some point i=
n
the future, but a bit too much at the moment being a newbie to snort3
and .lua files.
In my original post I asked if my assumption that if an 'alert' rule
triggered then a 'log' rule would not be executed. This seems to be how
a 'pass' rule works with 'alerts'. Can you help with this?
regards,
Brian


On 21/10/2024 08:55, Andrii Serbeniuk -X (aserbeni - SOFTSERVE INC at
Cisco) wrote:
> Hi Brian,
>
> Existing snort loggers don=92t have functionality to separate entries by
> event type, if you=92d like to have this behavior with any of them you
> could try logging all the events into a single file and managing it with
> some external script.
>
> Alternatively, you could take a look at this lua logger example from
> snort3_extra: https://github.com/snort3/snort3_extra/blob/master/src/
> loggers/alert_lua/alert.lua <https://github.com/snort3/snort3_extra/
> blob/master/src/loggers/alert_lua/alert.lua>
> With this you can implement your own steps during eventing, including
> file separation by event type.
>
> Hope this can be of use.
>
> Regards,
>
> Andrii
>
> *From: *Snort-users <[email protected]> on behalf of
> Brian Jameson via Snort-users <[email protected]>
> *Date: *Thursday, 17 October 2024 at 17:17
> *To: *[email protected] <[email protected]>
> *Subject: *[Snort-users] Snort3 logger of action type 'alert' and 'log'
>
> I have returned to snort after several years and am trying to get to
> know snort3. I have 'alerts' being logged to alert_csv, which goes on to
> record the data in MySQL. But I would also like to use an action type of
> 'log' for some rules. This is on the assumption that rules that trigger
> an alert will not go onto trigger a log. I would like to output the log
> alerts using something like the -A cmg but preferably to a file. Any
> suggestions on how to output two log types to seperate 'alert' and 'log'
> types? I assume this is done in snort.lua but where and how.
>
>
> _______________________________________________
> Snort-users mailing list
> [email protected]
> Go to this URL to change user options or unsubscribe:
> https://lists.snort.org/mailman/listinfo/snort-users <https://
> lists.snort.org/mailman/listinfo/snort-users>
>
>          To unsubscribe, send an email to:
>          [email protected]
>
> Please visit http://blog.snort.org <http://blog.snort.org> to stay
> current on all the latest Snort news!
>
> Please follow these rules: https://snort.org/faq/what-is-the-mailing-
> list-etiquette <https://snort.org/faq/what-is-the-mailing-list-etiquette>
>

--_000_SJ0PR11MB520022D97BC8A2713EC72EA8C54D2SJ0PR11MB5200namp_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc=
hemas-microsoft-com:office:word" xmlns:m=3D"http://schemas.microsoft.com/of=
fice/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Aptos;
	panose-1:2 11 0 4 2 2 2 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	font-size:12.0pt;
	font-family:"Aptos",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;
	mso-ligatures:none;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style>
</head>
<body lang=3D"en-UA" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea=
k-word">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US">Hi Brian,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US">Right, rule actions have priorities over one another=
 if multiple rules match at the same time, and if a higher priority action =
is triggered then lower priority ones
 won=92t be executed, by default.<br>
Config option responsible for this is =93event_queue.process_all_events=94,=
 which is false by default. By setting it to true, all rule actions will be=
 applied on the event.<br>
Config option responsible for the actions priority order is =93alerts.order=
=94, the default order is =93pass reject block react drop rewrite alert log=
 file_id=94.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US">Regards,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-f=
areast-language:EN-US">Andrii<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:EN-US"><o:p>&nbsp;</o:p></span></p>
<div id=3D"mail-editor-reference-message-container">
<div>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><b><span style=3D"col=
or:black">From:
</span></b><span style=3D"color:black">Brian Jameson &lt;[email protected]=
k&gt;<br>
<b>Date: </b>Wednesday, 23 October 2024 at 11:46<br>
<b>To: </b>Andrii Serbeniuk -X (aserbeni - SOFTSERVE INC at Cisco) &lt;aser=
[email protected]&gt;, [email protected] &lt;[email protected]=
.org&gt;<br>
<b>Subject: </b>Re: [Snort-users] Snort3 logger of action type 'alert' and =
'log'<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span style=3D"font-s=
ize:11.0pt">Andrii,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Thanks for the snort3_extra link=
. That will be good at some point in <br>
the future, but a bit too much at the moment being a newbie to snort3 <br>
and .lua files.<br>
In my original post I asked if my assumption that if an 'alert' rule <br>
triggered then a 'log' rule would not be executed. This seems to be how <br=
>
a 'pass' rule works with 'alerts'. Can you help with this?<br>
regards,<br>
Brian<br>
<br>
<br>
On 21/10/2024 08:55, Andrii Serbeniuk -X (aserbeni - SOFTSERVE INC at <br>
Cisco) wrote:<br>
&gt; Hi Brian,<br>
&gt; <br>
&gt; Existing snort loggers don=92t have functionality to separate entries =
by <br>
&gt; event type, if you=92d like to have this behavior with any of them you=
 <br>
&gt; could try logging all the events into a single file and managing it wi=
th <br>
&gt; some external script.<br>
&gt; <br>
&gt; Alternatively, you could take a look at this lua logger example from <=
br>
&gt; snort3_extra: </span><a href=3D"https://github.com/snort3/snort3_extra=
/blob/master/src/"><span style=3D"font-size:11.0pt">https://github.com/snor=
t3/snort3_extra/blob/master/src/</span></a><span style=3D"font-size:11.0pt"=
>
<br>
&gt; loggers/alert_lua/alert.lua &lt;https://github.com/snort3/snort3_extra=
/ <br>
&gt; blob/master/src/loggers/alert_lua/alert.lua&gt;<br>
&gt; With this you can implement your own steps during eventing, including =
<br>
&gt; file separation by event type.<br>
&gt; <br>
&gt; Hope this can be of use.<br>
&gt; <br>
&gt; Regards,<br>
&gt; <br>
&gt; Andrii<br>
&gt; <br>
&gt; *From: *Snort-users &lt;[email protected]&gt; on beh=
alf of <br>
&gt; Brian Jameson via Snort-users &lt;[email protected]&gt;<br>
&gt; *Date: *Thursday, 17 October 2024 at 17:17<br>
&gt; *To: *[email protected] &lt;[email protected]&gt;<=
br>
&gt; *Subject: *[Snort-users] Snort3 logger of action type 'alert' and 'log=
'<br>
&gt; <br>
&gt; I have returned to snort after several years and am trying to get to<b=
r>
&gt; know snort3. I have 'alerts' being logged to alert_csv, which goes on =
to<br>
&gt; record the data in MySQL. But I would also like to use an action type =
of<br>
&gt; 'log' for some rules. This is on the assumption that rules that trigge=
r<br>
&gt; an alert will not go onto trigger a log. I would like to output the lo=
g<br>
&gt; alerts using something like the -A cmg but preferably to a file. Any<b=
r>
&gt; suggestions on how to output two log types to seperate 'alert' and 'lo=
g'<br>
&gt; types? I assume this is done in snort.lua but where and how.<br>
&gt; <br>
&gt; <br>
&gt; _______________________________________________<br>
&gt; Snort-users mailing list<br>
&gt; [email protected]<br>
&gt; Go to this URL to change user options or unsubscribe:<br>
&gt; </span><a href=3D"https://lists.snort.org/mailman/listinfo/snort-users=
"><span style=3D"font-size:11.0pt">https://lists.snort.org/mailman/listinfo=
/snort-users</span></a><span style=3D"font-size:11.0pt"> &lt;https://
<br>
&gt; lists.snort.org/mailman/listinfo/snort-users&gt;<br>
&gt; <br>
&gt;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To unsubscribe, send =
an email to:<br>
&gt;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; snort-users-leave@lis=
ts.snort.org<br>
&gt; <br>
&gt; Please visit </span><a href=3D"http://blog.snort.org"><span style=3D"f=
ont-size:11.0pt">http://blog.snort.org</span></a><span style=3D"font-size:1=
1.0pt"> &lt;</span><a href=3D"http://blog.snort.org"><span style=3D"font-si=
ze:11.0pt">http://blog.snort.org</span></a><span style=3D"font-size:11.0pt"=
>&gt;
 to stay <br>
&gt; current on all the latest Snort news!<br>
&gt; <br>
&gt; Please follow these rules: </span><a href=3D"https://snort.org/faq/wha=
t-is-the-mailing-"><span style=3D"font-size:11.0pt">https://snort.org/faq/w=
hat-is-the-mailing-</span></a><span style=3D"font-size:11.0pt">
<br>
&gt; list-etiquette &lt;</span><a href=3D"https://snort.org/faq/what-is-the=
-mailing-list-etiquette"><span style=3D"font-size:11.0pt">https://snort.org=
/faq/what-is-the-mailing-list-etiquette</span></a><span style=3D"font-size:=
11.0pt">&gt;<br>
&gt; <o:p></o:p></span></p>
</div>
</div>
</div>
</div>
</div>
</body>
</html>

--_000_SJ0PR11MB520022D97BC8A2713EC72EA8C54D2SJ0PR11MB5200namp_--

--===============0745500618751042493==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============0745500618751042493==--