Sending snort logs to LogRhythm SIEM

677 views
Skip to first unread message

Monah Baki

unread,
Feb 25, 2015, 2:32:27 PM2/25/15
to securit...@googlegroups.com
Trying to follow the steps in https://blog.logrhythm.com/security/integrating-snort-alerts-with-logrhythm-via-barnyard2/


I just need the snort events, so in my barnyard2-1.conf:

output log_syslog_full: sensor_name $your_sensor_name, server $your_log_manager_ip, log_priority log_alert, operation_mode default


Nothing shows up in LogRhythm SIEM, and if I run tcpdump on my promiscuous interface on port 514, no results show up.


Thanks
Monah

Doug Burks

unread,
Feb 25, 2015, 7:58:35 PM2/25/15
to securit...@googlegroups.com
Hi Monah,

Please see:
https://code.google.com/p/security-onion/wiki/ThirdPartyIntegration#Support
> --
> You received this message because you are subscribed to the Google Groups "security-onion" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
> To post to this group, send email to securit...@googlegroups.com.
> Visit this group at http://groups.google.com/group/security-onion.
> For more options, visit https://groups.google.com/d/optout.



--
Doug Burks
Need Security Onion Training or Commercial Support?
http://securityonionsolutions.com

CB

unread,
Feb 27, 2015, 8:36:18 PM2/27/15
to securit...@googlegroups.com
Modify the config file /etc/nsm/<sensor name>/barnyard.conf

comment out the default line and enter:

output log_syslog_full: sensor_name <sensor name>, server <logRythm IP>, protocol udp, port 514, operation_mode default

if you want the packet data also:

output log_syslog_full: sensor_name <sensor name>, server <logRythm IP>, protocol udp, port 514, operation_mode complete

Ric Woodard

unread,
Mar 4, 2015, 10:23:32 AM3/4/15
to securit...@googlegroups.com
Monah, I've added the following line into each each barynard.conf file on every sensor and they forward successfully to my LogRhythm SIEM.

output log_syslog_full: sensor_name SENSOR-eth0-1, server LOGRHYTHMIP, log_priority log_alert, operation_mode default
Reply all
Reply to author
Forward
0 new messages