Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Column headers for downloaded Snort alert logs

    Scheduled Pinned Locked Moved IDS/IPS
    4 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jeffhammett
      last edited by

      Does anyone know what each column represents in the alert file (when you select Download from the Snort alerts page)

      It looks to me like it is (from left to right):

      Date
      first part of SID
      second part of SID
      ? - Not sure what this is
      Description
      Proto
      Source
      SPort
      Destination
      DPort
      ? - Not sure what this is
      Class
      ? - Not sure what this is

      If anyone can fill in the blanks on those three columns I haven't identified (or correct anything else I have wrong) it would be much appreciated.

      1 Reply Last reply Reply Quote 0
      • F
        fsansfil
        last edited by

        Date
        GID
        SID#
        SID version
        Description
        Proto
        Source
        SPort
        Destination
        DPort
        Class
        Class Priority

        1 Reply Last reply Reply Quote 0
        • J
          jeffhammett
          last edited by

          Thanks fsansfil, that looks good, but it looks like there might be one more column.

          Between the DPort and Class columns I have a column with large numbers. These numbers don't appear in the Alerts in the GUI, so I am having a hard time matching them up.

          Any help would be appreciated.

          1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks
            last edited by

            @jeffh:

            Thanks fsansfil, that looks good, but it looks like there might be one more column.

            Between the DPort and Class columns I have a column with large numbers. These numbers don't appear in the Alerts in the GUI, so I am having a hard time matching them up.

            Any help would be appreciated.

            That is the IP Header ID field.

            Bill

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.