Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: snort output server setup

$
0
0

Whats in your # syslog entry in your snort.conf?  It should look something similar to the following.

 

output alert_syslog: 1.1.1.1:514, LOG_AUTH LOG_ALERT.  We have ours going to user.log

 

You also want to make sure your running snort with the -s flag.  Which will allow it to be sent to a syslog.

 

You would also then set up a connector on the appliance to log to your facility.

 

Capture.JPG


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>