Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: alert_prelude Up: unified 2 Previous: unified 2   Contents

Format

output alert_unified2: filename <base file name> [, <limit <file size limit in MB> ] [, nostamp]
output log_unified2: filename <base file name> [, <limit <file size limit in MB>] [, nostamp]
output unified2: filename <base file name> [, <limit <file size limit in MB>] [, nostamp]

Figure 2.18: Unified Configuration Example
\begin{figure}\begin{verbatim}output alert_unified2: filename snort.alert, lim...
...put unified2: filename merged.log, limit 128, nostamp\end{verbatim}
\end{figure}



Steven Sturges 2008-04-01