Loading

Snort Integration

Stack 9.0.0 Serverless Observability Serverless Security

Version 1.19.1 (View all)
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic
Ingestion method(s) File, Network Protocol

This integration is for Snort.

This module has been developed against Snort v2.9 and v3, but is expected to work with other versions of Snort. This package is designed to read from the PFsense CSV output, the Alert Fast output either via reading a local logfile or receiving messages via syslog and the Snort 3 JSON log file.