Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Each snort alerts shows up twice in syslog

    IDS/IPS
    4
    7
    2.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      floz
      last edited by

      Hi there,

      I'm running Snort 2.9.7.0 pkg v3.2.3 on the latest 2.2 RELEASE of pfSense.

      Snort works fine (together with barnyard2 writing to SQL) but all alerts show up twice, see attached.

      This happening on both my testbed installs.

      Any idea why that might be the case? Interface config attached too. Thanks for any tips!!
      ![Screen Shot 2015-03-05 at 14.18.05.png](/public/imported_attachments/1/Screen Shot 2015-03-05 at 14.18.05.png)
      ![Screen Shot 2015-03-05 at 14.18.05.png_thumb](/public/imported_attachments/1/Screen Shot 2015-03-05 at 14.18.05.png_thumb)
      ![Screen Shot 2015-03-05 at 14.19.48.png](/public/imported_attachments/1/Screen Shot 2015-03-05 at 14.19.48.png)
      ![Screen Shot 2015-03-05 at 14.19.48.png_thumb](/public/imported_attachments/1/Screen Shot 2015-03-05 at 14.19.48.png_thumb)

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        @floz:

        Hi there,

        I'm running Snort 2.9.7.0 pkg v3.2.3 on the latest 2.2 RELEASE of pfSense.

        Snort works fine (together with barnyard2 writing to SQL) but all alerts show up twice, see attached.

        This happening on both my testbed installs.

        Any idea why that might be the case? Interface config attached too. Thanks for any tips!!

        That was a normal "quirk" of earlier pfSense versions.  I honestly thought it had been fixed in 2.2, but I have not paid careful attention to my own logs.  Do you by chance have Barnyard2 logging to syslog as well as SQL?

        EDIT: went back and checked my 2.2 system, and I am not getting double system log entries.

        Bill

        1 Reply Last reply Reply Quote 0
        • N
          Nullity
          last edited by

          I have always had occasional spans of double-posts in my logs. Considering that I had no obvious problems otherwise, I ignored it.

          Perhaps I should debug it…

          Please correct any obvious misinformation in my posts.
          -Not a professional; an arrogant ignoramous.

          1 Reply Last reply Reply Quote 0
          • F
            fsansfil
            last edited by

            Are you only seeing these doubles on Snort preprocessors rules ? (http_inspect, portscan, ssp_ssl)

            Do you see the same with ET or Snort VRT rules?

            F.

            1 Reply Last reply Reply Quote 0
            • F
              floz
              last edited by

              Thanks for your responses, fellows!

              @ bmeeks - no, barnyard is not set to log to syslog. Config attached.

              @ fsansfil - yes, seeing duplicates for all alerts, including e.g. ET…

              Also, in case you were wondering, neither snort nor barnyard are running twice:

              [2.2-RELEASE][admin@xxxxxxxxxxxxx]/root: ps aux | grep sno
              root  99679    0.7  2.1 2499540 2117944  -  SNs  12:06AM    18:14.44 /usr/local/bin/snort -R 28189 -D -q --suppress-config-log -l /var/log/snort/snort_bce028189 --pid-path /var/run --nolock-pidfile -G 28189 -c /usr/pbi/snort-amd64/etc/snort/snort_28189_bce0/snort.conf -i
              root  48491    0.0  0.1  118424   86080  -  Ss    8:09AM     3:01.54 /usr/local/bin/barnyard2 -r 28189 -f snort_28189_bce0.u2 --pid-path /var/run --nolock-pidfile -c /usr/pbi/snort-amd64/etc/snort/snort_28189_bce0/barnyard2.conf -d /var/log/snort/snort_bce028189 -D -q
              root  57369    0.0  0.0   18884    2388  0  S+    8:18AM     0:00.00 grep sno
              
              

              Screen_Shot_2015-03-06_at_08_09_40.png
              Screen_Shot_2015-03-06_at_08_09_40.png_thumb

              1 Reply Last reply Reply Quote 0
              • bmeeksB
                bmeeks
                last edited by

                Are any of the other system log entries (meaning non-Snort related ones) showing up twice?  As I mentioned, that used to be a quirk of the system logging process in older pfSense versions.  But I was thinking that got fixed back in 2.1.x.

                I don't know much about the internals of pfSense syslog.  Maybe one of the developers will see this thread and chime in.

                Bill

                1 Reply Last reply Reply Quote 0
                • F
                  floz
                  last edited by

                  Hi Bill,

                  No, no duplicates otherwise, just snort alerts (but not, eg. snort startup notices).

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.