I have been working with snort-IDS. I have got some log files at /var/log/snort. The files are of type snort.log.xxxx. How do i view this file???
I have been working with snort-IDS. I have got some log files at /var/log/snort. The files are of type snort.log.xxxx. How do i view this file???
1.Bro first you have to move to the snort log folder.
$cd /var/log/snort
2.Now list the contents of the folder using the command below.
$ls
3.Then you can see files like(for example in my case) as below.
alert tcpdump.log.67488231 tcpdump.log.56738523
4.Suppose if you are trying to open this "tcpdump.log.67488231" (tcpdump.log.67488231- this is a sample log file capture by my system. So in each of your case it must be different sequence number) file,you can not read the data inside the file.So in order to clearly read or understand what is inside the file, you can use following command.
$sudo tcpdump -r tcpdump.log.67488231
5.Now the file open and you can read the content.
OR
You can use the command below
$sudo snort -r snort.log.5637972
(snort.log.5637972 is the sample file you can find it inside the same snort log file( /var/log/snort). After starting snort as IDS mode we will get a file like this. In order to read this file use the above command)