Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Format Up: Output Modules Previous: Format   Contents

unified 2

The unified2 output plugin is a replacement for the unified output plugin. It has the same performance characteristics, but a slightly different logging format. See section [*] on unified logging for more information.

Unified2 can work in one of three modes, packet logging, alert logging, or true unified logging. Packet logging includes a capture of the entire packet and is specified with log_unfied2. Likewise, alert logging will only log events and is specified with alert_unified2. To include both logging styles in a single, unified file, simply specify unified2.

Note:   By default, unified 2 files have the file creation time (in Unix Epoch format) appended to each file when it is created.



Subsections

Steven Sturges 2007-10-04