Snort mailing list archives

Re: unified format


From: "Roland Turner (SourceForge)" <raz.fs.arg () countersnipe com>
Date: Fri, 19 Aug 2005 10:36:45 +0100 (BST)

Igor Belikov said:


 1. In archive of this mailing list I read that unified alert file
 contains only alerts information, and unified log file contains both
 alerts and corresponding payloads. But documentation says different:
 unified log contains only payload, and I confirmed this by some
 tests.


The unified log format does not contain broken out fields for
protocol-number or src/dest ip-address/port-number, while the unified
alert format does. This information is, however, still available in the
payload in the unified log format. The gen:sid:rev, classification,
priority, eventid and timestamps are presented identically in both formats
as part of the Event struct.

- Raz




-------------------------------------------------------
SF.Net email is Sponsored by the Better Software Conference & EXPO
September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: