Skip to content
This repository has been archived by the owner on Jan 18, 2024. It is now read-only.

Barnyard2 2.1.13 sending alerts to remote syslog server. #243

Open
jdpadro opened this issue Dec 5, 2018 · 0 comments
Open

Barnyard2 2.1.13 sending alerts to remote syslog server. #243

jdpadro opened this issue Dec 5, 2018 · 0 comments

Comments

@jdpadro
Copy link

jdpadro commented Dec 5, 2018

I entered the following string into my conf file;

output alert_syslog_full: sensor_name lrc-eno2, server syslog.xxx.xxxx.xxx, protocol tcp, port 514, log_priority log_alert, operation_mode default

The strig works great with the exception of the MSGHDR which typically has a value of "snort" to identify it as a snort alert. I use this to filter it into an Index on our centralized syslog server to enhane searching. With this said, I am hoping that someone knows how to add a custom field that will export from Barnyard so that I can tag it as "snort"

Thank you

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant