Snort 3.5 Logging Packets to a PCAP File of a Triggered Alert

Justin Forte via Snort-users <[email protected]> Thu, 14 Nov 2024 19:15:21 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <SJ0PR09MB96351EAE1E974999002F3E43915B2@SJ0PR09MB9635.namprd09.prod.outlook.com>
--===============2663154731060629472==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_SJ0PR09MB96351EAE1E974999002F3E43915B2SJ0PR09MB9635namp_"

--_000_SJ0PR09MB96351EAE1E974999002F3E43915B2SJ0PR09MB9635namp_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hello,

I have a question hopefully I can get an answer for.  I am new to Snort and=
 have been tasked with upgrading our IDS boxes with Snort from 2.9.20 to 3.=
5.  I have everything setup except for I am having issues with recreating a=
 process from our Snort 2.9.20 system.  Currently on our 2.9.20 build it is=
 setup to log triggered alerts and then captures and logs PCAPs around the =
triggered alert.  I can get the alert_json configured how I want and it wil=
l work.  I have attempted to use pcap_log with defaults but the pcap file d=
oes not populate to store the packets.  I can add the -L and add pcap or lo=
g_pcap but this captures all the packets, which is not something we want at=
 this time.  Can anyone guide me in a way I can configure packets to be cap=
tured to a pcap file around a triggered alert?

Thanks,
Justin Forte
IT Cybersecurity Analyst I
O: 417.831.8838


[City Utilities]

[City Utilities]<http://www.cityutilities.net>

PO Box 551 | Springfield, MO 65801-0551
cityutilities.net<http://www.cityutilities.net>

--_000_SJ0PR09MB96351EAE1E974999002F3E43915B2SJ0PR09MB9635namp_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	font-size:11.0pt;
	font-family:"Aptos",sans-serif;
	mso-ligatures:standardcontextual;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Aptos",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:11.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"#467886" vlink=3D"#96607D" style=3D"word-wrap:=
break-word">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">Hello,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">I have a question hopefully I can get an answer for.=
&nbsp; I am new to Snort and have been tasked with upgrading our IDS boxes =
with Snort from 2.9.20 to 3.5.&nbsp; I have everything setup except for I a=
m having issues with recreating a process from
 our Snort 2.9.20 system.&nbsp; Currently on our 2.9.20 build it is setup t=
o log triggered alerts and then captures and logs PCAPs around the triggere=
d alert.&nbsp; I can get the alert_json configured how I want and it will w=
ork.&nbsp; I have attempted to use pcap_log with
 defaults but the pcap file does not populate to store the packets.&nbsp; I=
 can add the -L and add pcap or log_pcap but this captures all the packets,=
 which is not something we want at this time.&nbsp; Can anyone guide me in =
a way I can configure packets to be captured
 to a pcap file around a triggered alert?<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Thanks,<o:p></o:p></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;margin-bottom:12.0p=
t"><span style=3D"font-size:10.0pt;font-family:&quot;Arial&quot;,sans-serif=
;color:black;mso-ligatures:none">Justin Forte<br>
IT Cybersecurity Analyst I<br>
O: 417.831.8838<o:p></o:p></span></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p><font face=3D"Arial" size=3D"1px"><br>
<img src=3D"https://www.cityutilities.net/wp-content/uploads/email-divbar.j=
pg" height=3D"12" width=3D"300" border=3D"0" alt=3D"City Utilities"><br>
<br>
<a href=3D"http://www.cityutilities.net" target=3D"_blank" title=3D"Link: C=
ity Utilities" border=3D"0"><img src=3D"https://www.cityutilities.net/wp-co=
ntent/uploads/email-culogo.png" height=3D"75" width=3D"125" border=3D"0" al=
t=3D"City Utilities"></a><br>
<br>
</font><font face=3D"Arial" size=3D"2">PO Box 551 | Springfield, MO 65801-0=
551<br>
<a href=3D"http://www.cityutilities.net" target=3D"_blank" title=3D"Link: C=
ity Utilities" border=3D"0">cityutilities.net</a></font></p>
</body>
</html>

--_000_SJ0PR09MB96351EAE1E974999002F3E43915B2SJ0PR09MB9635namp_--

--===============2663154731060629472==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============2663154731060629472==--