Snort mailing list archives

Re: RE: Alert OR syslog?


From: Erek Adams <erek () theadamsfamily net>
Date: Fri, 6 Dec 2002 11:26:26 -0800 (PST)

On Fri, 6 Dec 2002, L. Christopher Luther wrote:

Snort's command line directives sometimes do "strange" (my opinion only)
things, so it is possible that by specifying two alert facilities on the
command line, one is taking precedence over the other.

The basica assumption is that since you've put something on the command
line, it should be what you want 'right now'.  Anything listed on the
command line will _override_ whatever you have in the .conf file.

Instead, I use output directives in the snort.conf file to specify multiple
log and/or alert facilities.  Have you tried placing the following in your
snort.conf:

output alert_full: alert.ids
alert_syslog: LOG_AUTH LOG_ALERT

And removing the "-A fast" and "-s" command line options?  This will alert
first to the ASCII file alert.ids, then to the syslog facility.

Right.  Perfect way to do it.

One other thing you can do is to define a 'custom rule type' that includes
both syslog and full alerts.

Side note:  Why don't you log to binary, re-run the binary pcaps thru
snort and have it generate the text files (maybe even syslog stuff) at a
later time.  Only wanting the syslog output for watching/tailing would
stop you from doing that...

Cheers!

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: