• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Snort and syslog.

Scheduled Pinned Locked Moved pfSense Packages
6 Posts 2 Posters 3.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • V
    vleinone
    last edited by Feb 14, 2007, 6:13 AM

    Hi all,

    Is there any possibility to send snort alerts to syslog server?

    Br,

    Ville

    1 Reply Last reply Reply Quote 0
    • S
      sullrich
      last edited by Feb 14, 2007, 6:14 AM

      Not sure that this will work ATM.  You can always remotely query it with exec_raw.php, however.

      1 Reply Last reply Reply Quote 0
      • V
        vleinone
        last edited by Feb 14, 2007, 6:49 AM

        Thanks for info.

        This would be nice feature if you have central syslog-server.

        Do anyone knows if its impossible to compile that feature inside
        snort? Because there is that syslog line, but i think that is not
        taken part of this compiling configuration.

        Br,

        Ville

        1 Reply Last reply Reply Quote 0
        • S
          sullrich
          last edited by Feb 14, 2007, 4:15 PM

          Actually I just checked, snort is already sending items to the primary logging tab which should work with remote syslog.

          1 Reply Last reply Reply Quote 0
          • V
            vleinone
            last edited by Feb 15, 2007, 6:09 AM

            Hi,

            True if you mean "Diagnostics: System logs: System" page, but it send
            only blocked information, not full alert (right).

            I want to send syslog "Services: Snort: Snort Alerts" page information.

            Br,

            Ville

            1 Reply Last reply Reply Quote 0
            • S
              sullrich
              last edited by Feb 15, 2007, 3:25 PM

              @vleinone:

              Hi,

              True if you mean "Diagnostics: System logs: System" page, but it send
              only blocked information, not full alert (right).

              I want to send syslog "Services: Snort: Snort Alerts" page information.

              Br,

              Ville

              Oh okay, yeah that won't work currently.

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received