Snort 3.5 Logging Packets to a PCAP File of a Triggered Alert
Justin Forte via Snort-users <[email protected]> Thu, 14 Nov 2024 19:15:21 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <SJ0PR09MB96351EAE1E974999002F3E43915B2@SJ0PR09MB9635.namprd09.prod.outlook.com> |
--===============2663154731060629472==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_SJ0PR09MB96351EAE1E974999002F3E43915B2SJ0PR09MB9635namp_"
--_000_SJ0PR09MB96351EAE1E974999002F3E43915B2SJ0PR09MB9635namp_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Hello,
I have a question hopefully I can get an answer for. I am new to Snort and=
have been tasked with upgrading our IDS boxes with Snort from 2.9.20 to 3.=
5. I have everything setup except for I am having issues with recreating a=
process from our Snort 2.9.20 system. Currently on our 2.9.20 build it is=
setup to log triggered alerts and then captures and logs PCAPs around the =
triggered alert. I can get the alert_json configured how I want and it wil=
l work. I have attempted to use pcap_log with defaults but the pcap file d=
oes not populate to store the packets. I can add the -L and add pcap or lo=
g_pcap but this captures all the packets, which is not something we want at=
this time. Can anyone guide me in a way I can configure packets to be cap=
tured to a pcap file around a triggered alert?
Thanks,
Justin Forte
IT Cybersecurity Analyst I
O: 417.831.8838
[City Utilities]
[City Utilities]<http://www.cityutilities.net>
PO Box 551 | Springfield, MO 65801-0551
cityutilities.net<http://www.cityutilities.net>
--_000_SJ0PR09MB96351EAE1E974999002F3E43915B2SJ0PR09MB9635namp_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Aptos",sans-serif;
mso-ligatures:standardcontextual;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Aptos",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:11.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"#467886" vlink=3D"#96607D" style=3D"word-wrap:=
break-word">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">Hello,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">I have a question hopefully I can get an answer for.=
I am new to Snort and have been tasked with upgrading our IDS boxes =
with Snort from 2.9.20 to 3.5. I have everything setup except for I a=
m having issues with recreating a process from
our Snort 2.9.20 system. Currently on our 2.9.20 build it is setup t=
o log triggered alerts and then captures and logs PCAPs around the triggere=
d alert. I can get the alert_json configured how I want and it will w=
ork. I have attempted to use pcap_log with
defaults but the pcap file does not populate to store the packets. I=
can add the -L and add pcap or log_pcap but this captures all the packets,=
which is not something we want at this time. Can anyone guide me in =
a way I can configure packets to be captured
to a pcap file around a triggered alert?<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Thanks,<o:p></o:p></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;margin-bottom:12.0p=
t"><span style=3D"font-size:10.0pt;font-family:"Arial",sans-serif=
;color:black;mso-ligatures:none">Justin Forte<br>
IT Cybersecurity Analyst I<br>
O: 417.831.8838<o:p></o:p></span></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
</div>
<p><font face=3D"Arial" size=3D"1px"><br>
<img src=3D"https://www.cityutilities.net/wp-content/uploads/email-divbar.j=
pg" height=3D"12" width=3D"300" border=3D"0" alt=3D"City Utilities"><br>
<br>
<a href=3D"http://www.cityutilities.net" target=3D"_blank" title=3D"Link: C=
ity Utilities" border=3D"0"><img src=3D"https://www.cityutilities.net/wp-co=
ntent/uploads/email-culogo.png" height=3D"75" width=3D"125" border=3D"0" al=
t=3D"City Utilities"></a><br>
<br>
</font><font face=3D"Arial" size=3D"2">PO Box 551 | Springfield, MO 65801-0=
551<br>
<a href=3D"http://www.cityutilities.net" target=3D"_blank" title=3D"Link: C=
ity Utilities" border=3D"0">cityutilities.net</a></font></p>
</body>
</html>
--_000_SJ0PR09MB96351EAE1E974999002F3E43915B2SJ0PR09MB9635namp_--
--===============2663154731060629472==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
--===============2663154731060629472==--