Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Snort check for rule updates appearing as syslog errs, not info severity

    IDS/IPS
    2
    3
    464
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      firewalluser last edited by

      Services: Snort 2.9.7.3 pkg v3.2.6

      The Snort_check_for_rule_updates.php is posting its update/download status to the "err"or syslog severity status, perhaps syslog severity info would be better?

      1 Reply Last reply Reply Quote 0
      • bmeeks
        bmeeks last edited by

        The package is using a pfSense system call to log messages to the system log.  The only two pfSense system function calls I am aware of are log_error() and log_auth().  The former logs with Severity ERROR and the latter with Facility AUTH.  There is no way to pass a custom Severity or Facility to those system calls.

        Generally the preference of the developer team is to use pfSense system calls when available.  It would be nice if one or both of those system functions would let you pass a Facility and Severity as optional parameters.

        Bill

        1 Reply Last reply Reply Quote 0
        • F
          firewalluser last edited by

          So limited API functionality in a way then.

          Ok thanks for letting me know, I'll add some exception rules for the monitoring system.  :)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post

          Products

          • Platform Overview
          • TNSR
          • pfSense
          • Appliances

          Services

          • Training
          • Professional Services

          Support

          • Subscription Plans
          • Contact Support
          • Product Lifecycle
          • Documentation

          News

          • Media Coverage
          • Press
          • Events

          Resources

          • Blog
          • FAQ
          • Find a Partner
          • Resource Library
          • Security Information

          Company

          • About Us
          • Careers
          • Partners
          • Contact Us
          • Legal
          Our Mission

          We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

          Subscribe to our Newsletter

          Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

          © 2021 Rubicon Communications, LLC | Privacy Policy