Snort mailing list archives

Re: snort output logging to two places at the same time


From: "Paul Melson" <pmelson () gmail com>
Date: Fri, 27 Apr 2007 10:23:10 -0400

-----Original Message-----
However, I am just wondering if Snort is able to log to both unified log
format as well as syslog format 
at the same time too? 

E.g. in snort config I specify

output syslog: LOG_ALERT
output log_unified: filename snort.log, limit 128

Anyone tried this before? Appreciate your response.

Yes, this works just fine.  

PaulM


-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: