Snort mailing list archives
Re: RE: Alert OR syslog?
From: Erek Adams <erek () theadamsfamily net>
Date: Fri, 6 Dec 2002 11:26:26 -0800 (PST)
On Fri, 6 Dec 2002, L. Christopher Luther wrote:
Snort's command line directives sometimes do "strange" (my opinion only) things, so it is possible that by specifying two alert facilities on the command line, one is taking precedence over the other.
The basica assumption is that since you've put something on the command line, it should be what you want 'right now'. Anything listed on the command line will _override_ whatever you have in the .conf file.
Instead, I use output directives in the snort.conf file to specify multiple log and/or alert facilities. Have you tried placing the following in your snort.conf: output alert_full: alert.ids alert_syslog: LOG_AUTH LOG_ALERT And removing the "-A fast" and "-s" command line options? This will alert first to the ASCII file alert.ids, then to the syslog facility.
Right. Perfect way to do it. One other thing you can do is to define a 'custom rule type' that includes both syslog and full alerts. Side note: Why don't you log to binary, re-run the binary pcaps thru snort and have it generate the text files (maybe even syslog stuff) at a later time. Only wanting the syslog output for watching/tailing would stop you from doing that... Cheers! ----- Erek Adams Nifty-Type-Guy TheAdamsFamily.Net ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Alert OR syslog? Weiss, Jeffrey H. (Dec 05)
- Re: Alert OR syslog? Alberto Gonzalez (Dec 05)
- <Possible follow-ups>
- RE: Alert OR syslog? Weiss, Jeffrey H. (Dec 05)
- RE: Alert OR syslog? Don (Dec 05)
- RE: Alert OR syslog? Don (Dec 05)
- RE: Alert OR syslog? Don (Dec 05)
- RE: Alert OR syslog? Steve Halligan (Dec 05)
- RE: Alert OR syslog? Weiss, Jeffrey H. (Dec 05)
- Re: Alert OR syslog? Alberto Gonzalez (Dec 05)
- RE: Alert OR syslog? Weiss, Jeffrey H. (Dec 05)
- RE: Alert OR syslog? L. Christopher Luther (Dec 06)
- Re: RE: Alert OR syslog? Erek Adams (Dec 06)