Snort
ArchivedThe Snort application normalizes Snort events and enables you to analyze Snort data using pre-set dashboard views. You can further customize the dashboard and searches to perform in-depth analysis.
Release Details
Package Details
- Dashboard Package
- LP_Snort
- Label Package
- LP_Snort
- Normalization Package
- LP_Snort
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Installation
Follow these steps to install the Snort v5.0.0 plugin:
- Download the Snort package from the Download section above.
- Add the required Snort as a device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Important Notice
All the normalized field names used in this application are checked and aligned with the LogPoint taxonomy.
Log Format
Expected Log Source
Snort
Log Sample
<38>Oct 23 06:36:25 snort snort[6153]: [139:1:1] (spp_sdf) SDF Combination Alert [Classification: Sensitive Data was Transmitted Across the Network] [Priority: 2] {TCP} 1.1.1.1 -> 1.1.1.2
To export data to LogPoint use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.