<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Snort and alert modes. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snort-and-alert-modes/m-p/5136353#M1113812</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;At the beginning I have a lot of problem with&amp;nbsp;information chaos with the differences between Snort 2 and Snort 3. There are plenty books and info about Snort 2, but not many about Snort 3. For example Snort 2 Manual (y. 2020) is 270 page book and but Snort 3 Manual (y. 2024) is 116 page book and there is very little info.&lt;/P&gt;&lt;P&gt;I can only&amp;nbsp;guess what is the latest&amp;nbsp;approach in using Snort 3, for example thanks to the latest videotutorials on YT.&amp;nbsp; I really miss the forum on Snort to not making spam for example here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To the point, there are up-to-date such logger modules in Snort (alerts and packet logger).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mariolak3_0-1719404339516.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221659i5935E05EEA60E1FF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mariolak3_0-1719404339516.png" alt="mariolak3_0-1719404339516.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;At this point, I used alert_fast, alert_full and alert_json, because I found tutorial which recomended alert_json because there is possibility to integrate this with Splunk (I found myself alert_fast and alert_full too). OK. I did that.&lt;/P&gt;&lt;P&gt;But, what with unified2? The old materials tell a lot about it. But now, nothing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;From Snort 2 manual:&lt;BR /&gt;Unified2 can work in one of threemodes, packet logging (log_unified), alert logging (alert_unified2), or true unified logging(unified2).&lt;/P&gt;&lt;P&gt;In Snort 3 Manual is mentioned only about unified2.&lt;/P&gt;&lt;P&gt;Is unified2 mode is used by anyone? Or this is only history? Is Snort 3&amp;nbsp;at all&amp;nbsp;is able to use log_unified, alert_unified2 or only unified2(packet and alert)?&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jun 2024 13:23:02 GMT</pubDate>
    <dc:creator>mariolak3</dc:creator>
    <dc:date>2024-06-26T13:23:02Z</dc:date>
    <item>
      <title>Snort and alert modes.</title>
      <link>https://community.cisco.com/t5/network-security/snort-and-alert-modes/m-p/5136353#M1113812</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;At the beginning I have a lot of problem with&amp;nbsp;information chaos with the differences between Snort 2 and Snort 3. There are plenty books and info about Snort 2, but not many about Snort 3. For example Snort 2 Manual (y. 2020) is 270 page book and but Snort 3 Manual (y. 2024) is 116 page book and there is very little info.&lt;/P&gt;&lt;P&gt;I can only&amp;nbsp;guess what is the latest&amp;nbsp;approach in using Snort 3, for example thanks to the latest videotutorials on YT.&amp;nbsp; I really miss the forum on Snort to not making spam for example here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To the point, there are up-to-date such logger modules in Snort (alerts and packet logger).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mariolak3_0-1719404339516.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221659i5935E05EEA60E1FF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mariolak3_0-1719404339516.png" alt="mariolak3_0-1719404339516.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;At this point, I used alert_fast, alert_full and alert_json, because I found tutorial which recomended alert_json because there is possibility to integrate this with Splunk (I found myself alert_fast and alert_full too). OK. I did that.&lt;/P&gt;&lt;P&gt;But, what with unified2? The old materials tell a lot about it. But now, nothing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;From Snort 2 manual:&lt;BR /&gt;Unified2 can work in one of threemodes, packet logging (log_unified), alert logging (alert_unified2), or true unified logging(unified2).&lt;/P&gt;&lt;P&gt;In Snort 3 Manual is mentioned only about unified2.&lt;/P&gt;&lt;P&gt;Is unified2 mode is used by anyone? Or this is only history? Is Snort 3&amp;nbsp;at all&amp;nbsp;is able to use log_unified, alert_unified2 or only unified2(packet and alert)?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 13:23:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort-and-alert-modes/m-p/5136353#M1113812</guid>
      <dc:creator>mariolak3</dc:creator>
      <dc:date>2024-06-26T13:23:02Z</dc:date>
    </item>
  </channel>
</rss>

