Snort mailing list archives
Re: How to log as ASCII?
From: Erek Adams <erek () snort org>
Date: Wed, 14 May 2003 11:37:07 -0400 (EDT)
On Wed, 14 May 2003 peter.grosse-hering () ps ge com wrote:
How can I log into a plain ASCII files in the same format as alert_full? We also want to avoid those subdirectory structures, but need just a plain ASCII file where all "Log"-rules log into...
Well... I'm not quite sure what you mean. Full and Fast alert modes both _are_ ASCII files. If you want the packet decoded and the payload listed in the alert files, as you have in the <log_dir>/<IP_Address>/<whatever> files, you can't. I think a viable option would be to log in binary (pcap), then post process the file to examine the packet and the alert. Once you have a pcap file, do something like: snort -dvr <file> |more And you'll have the full packet dump as in the directories, but without all the files and subdirs. Cheers! ----- Erek Adams "When things get weird, the weird turn pro." H.S. Thompson ------------------------------------------------------- Enterprise Linux Forum Conference & Expo, June 4-6, 2003, Santa Clara The only event dedicated to issues related to Linux enterprise solutions www.enterpriselinuxforum.com _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- How to log as ASCII? peter . grosse-hering (May 14)
- Re: How to log as ASCII? Erek Adams (May 14)