Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Format Up: Output Modules Previous: Format   Contents

unified 2

The unified2 output plugin is a replacement for the unified output plugin. It has the same performance characteristics, but a slightly different logging format. See section 2.4.8 on unified logging for more information.

Unified2 can work in one of three modes, packet logging, alert logging, or true unified logging. Packet logging includes a capture of the entire packet and is specified with log_unified2. Likewise, alert logging will only log events and is specified with alert_unified2. To include both logging styles in a single, unified file, simply specify unified2.

Note:   By default, unified 2 files have the file creation time (in Unix Epoch format) appended to each file when it is created.



Subsections

Steven Sturges 2008-04-01