Skip to content
Merged
Show file tree
Hide file tree
Changes from 7 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions packages/snort/_dev/build/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,9 @@ This integration is for [Snort](https://www.snort.org/).

## Compatibility

This module has been developed against Snort v2.9, but is expected to work
with other versions of Snort. This package is designed to read from the PFsense CSV output
and the Alert Fast output either via reading a local logfile or receiving messages via syslog
This module has been developed against Snort v2.9 and v3, but is expected to work
with other versions of Snort. This package is designed to read from the PFsense CSV output,
the Alert Fast output either via reading a local logfile or receiving messages via syslog and the Snort 3 JSON log file.

## Log

Expand Down
5 changes: 5 additions & 0 deletions packages/snort/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "1.1.0"
changes:
- description: Add Snort 3 JSON support.
type: enhancement
link: https://github.com/elastic/integrations/pull/3876
- version: "1.0.0"
changes:
- description: Make GA
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,4 @@
dynamic_fields:
event.created: "^[0-9]{4}(-[0-9]{2}){2}T[0-9]{2}(:[0-9]{2}){2}\\.[0-9]{3}-[0-9]{2}:[0-9]{2}$"
event.ingested: ".*"
"@timestamp": "^[0-9]{4}(-[0-9]{2}){2}T[0-9]{2}(:[0-9]{2}){2}\\.[0-9]{3}-[0-9]{2}:[0-9]{2}$"
fields:
"@timestamp": "2020-04-28T11:07:58.223Z"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,14 +15,15 @@
"category": [
"network"
],
"created": "2022-09-04T21:45:37.536-05:00",
"created": "2020-04-28T11:07:58.223Z",
"kind": "alert",
"original": "09/04-21:45:37.536335 ,1,1000006,0,\"TCP connection\",TCP,10.100.20.59,57263,10.100.10.190,22,00:25:90:3A:05:13,00:50:56:9D:A5:BE,0x72,***AP***,0x688F0DFC,0xBC763516,,0x80C,127,0,55665,100,102400,,,,",
"timezone": "America/Chicago"
},
"network": {
"community_id": "1:mnJdrIaujYJdP8lXFem/hodYAt0=",
"direction": "internal",
"iana_number": "6",
"transport": "tcp",
"type": "ipv4"
},
Expand All @@ -49,7 +50,7 @@
"eth": {
"length": 114
},
"gid": 1,
"gid": "1",
"ip": {
"id": 55665,
"length": 102400,
Expand Down Expand Up @@ -88,14 +89,15 @@
"category": [
"network"
],
"created": "2022-09-04T21:45:37.553-05:00",
"created": "2020-04-28T11:07:58.223Z",
"kind": "alert",
"original": "09/04-21:45:37.553882 ,1,1000006,0,\"TCP connection\",TCP,10.100.20.59,57263,10.100.10.190,22,00:25:90:3A:05:13,00:50:56:9D:A5:BE,0x72,***AP***,0x688F0E38,0xBC763552,,0x80C,127,0,55666,100,102400,,,,",
"timezone": "America/Chicago"
},
"network": {
"community_id": "1:mnJdrIaujYJdP8lXFem/hodYAt0=",
"direction": "internal",
"iana_number": "6",
"transport": "tcp",
"type": "ipv4"
},
Expand All @@ -122,7 +124,7 @@
"eth": {
"length": 114
},
"gid": 1,
"gid": "1",
"ip": {
"id": 55666,
"length": 102400,
Expand Down Expand Up @@ -161,14 +163,15 @@
"category": [
"network"
],
"created": "2022-09-04T21:50:40.017-05:00",
"created": "2020-04-28T11:07:58.223Z",
"kind": "alert",
"original": "09/04-21:50:40.017935 ,1,1000005,0,\"UDP Connection\",UDP,10.100.10.1,53,10.100.10.190,55475,00:25:90:3A:05:13,00:50:56:9D:A5:BE,0xC1,,,,,,64,0,56094,179,183296,,,,",
"timezone": "America/Chicago"
},
"network": {
"community_id": "1:wvunc3EtDmKBjBft1PFlQ2pSLzw=",
"direction": "internal",
"iana_number": "17",
"transport": "udp",
"type": "ipv4"
},
Expand All @@ -195,7 +198,7 @@
"eth": {
"length": 193
},
"gid": 1,
"gid": "1",
"ip": {
"id": 56094,
"length": 183296,
Expand Down Expand Up @@ -231,14 +234,15 @@
"category": [
"network"
],
"created": "2022-09-04T21:50:39.947-05:00",
"created": "2020-04-28T11:07:58.223Z",
"kind": "alert",
"original": "09/04-21:50:39.947383 ,1,1000005,0,\"UDP Connection\",UDP,10.100.10.1,53,10.100.10.190,55333,00:25:90:3A:05:13,00:50:56:9D:A5:BE,0xB1,,,,,,64,0,26112,163,166912,,,,",
"timezone": "America/Chicago"
},
"network": {
"community_id": "1:IcqpMEB/fJpNhZgyJVhx8VHROwY=",
"direction": "internal",
"iana_number": "17",
"transport": "udp",
"type": "ipv4"
},
Expand All @@ -265,7 +269,7 @@
"eth": {
"length": 177
},
"gid": 1,
"gid": "1",
"ip": {
"id": 26112,
"length": 166912,
Expand Down Expand Up @@ -301,14 +305,15 @@
"category": [
"network"
],
"created": "2022-09-04T21:50:40.666-05:00",
"created": "2020-04-28T11:07:58.223Z",
"kind": "alert",
"original": "09/04-21:50:40.666095 ,1,1000005,0,\"UDP Connection\",UDP,10.100.10.75,55776,10.100.10.255,32414,00:0C:29:B8:43:CE,FF:FF:FF:FF:FF:FF,0x3F,,,,,,64,0,37712,49,50176,,,,",
"timezone": "America/Chicago"
},
"network": {
"community_id": "1:NW0wNEOLThLuO4EsoJXFbyp6zII=",
"direction": "internal",
"iana_number": "17",
"transport": "udp",
"type": "ipv4"
},
Expand All @@ -335,7 +340,7 @@
"eth": {
"length": 63
},
"gid": 1,
"gid": "1",
"ip": {
"id": 37712,
"length": 50176,
Expand Down Expand Up @@ -382,14 +387,15 @@
"category": [
"network"
],
"created": "2022-09-04T21:49:55.900-05:00",
"created": "2020-04-28T11:07:58.223Z",
"kind": "alert",
"original": "09/04-21:49:55.900215 ,1,1000004,0,\"Pinging...\",ICMP,10.100.10.190,,175.16.199.1,,00:50:56:9D:A5:BE,00:25:90:3A:05:13,0x62,,,,,,64,0,37607,84,86016,8,0,83,1",
"timezone": "America/Chicago"
},
"network": {
"community_id": "1:jEaJsIOzda45Q8FjN0LeZEATihA=",
"direction": "outbound",
"iana_number": "1",
"transport": "icmp",
"type": "ipv4"
},
Expand All @@ -416,7 +422,7 @@
"eth": {
"length": 98
},
"gid": 1,
"gid": "1",
"icmp": {
"code": 0,
"id": 83,
Expand Down Expand Up @@ -456,14 +462,15 @@
"category": [
"network"
],
"created": "2022-09-04T21:49:55.911-05:00",
"created": "2020-04-28T11:07:58.223Z",
"kind": "alert",
"original": "09/04-21:49:55.911592 ,1,1000004,0,\"Pinging...\",ICMP,175.16.199.1,,10.100.10.190,,00:25:90:3A:05:13,00:50:56:9D:A5:BE,0x62,,,,,,54,0,23522,84,86016,0,0,83,1",
"timezone": "America/Chicago"
},
"network": {
"community_id": "1:PsO7nB0G1KDZ1IDLocfXBmcxiaA=",
"direction": "inbound",
"iana_number": "1",
"transport": "icmp",
"type": "ipv4"
},
Expand All @@ -490,7 +497,7 @@
"eth": {
"length": 98
},
"gid": 1,
"gid": "1",
"icmp": {
"code": 0,
"id": 83,
Expand Down Expand Up @@ -554,14 +561,15 @@
"category": [
"network"
],
"created": "2022-09-04T21:49:56.900-05:00",
"created": "2020-04-28T11:07:58.223Z",
"kind": "alert",
"original": "09/04-21:49:56.900997 ,1,1000004,0,\"Pinging...\",ICMP,10.100.10.190,,175.16.199.1,,00:50:56:9D:A5:BE,00:25:90:3A:05:13,0x62,,,,,,64,0,37636,84,86016,8,0,83,2",
"timezone": "America/Chicago"
},
"network": {
"community_id": "1:jEaJsIOzda45Q8FjN0LeZEATihA=",
"direction": "outbound",
"iana_number": "1",
"transport": "icmp",
"type": "ipv4"
},
Expand All @@ -588,7 +596,7 @@
"eth": {
"length": 98
},
"gid": 1,
"gid": "1",
"icmp": {
"code": 0,
"id": 83,
Expand Down
Loading