[Snort-users] Syslog Alert format?

JP Vossen vossenjp at ...8683...
Thu Dec 11 22:00:00 EST 2003

There is probably an obvious answer to this, but if so it's eluding me at the
moment.  I see a lot of Snort events from a lot of customer networks from all
over the world.  Every once in a while I see syslog alerts that are different
than I expect.  I have a ton of regular expressions to filter things, and I
get odd stuff that doesn't match.

For example, I'm getting this one, note the missing src and dst ports (made
up IPs):

...BAD-TRAFFIC bad frag bits [Classification: Misc activity] [Priority: 3]:
{TCP} ->

I'm expecting something like this:
	{TCP} ->

Off the top of my head, I don't even know how to do that on purpose!  How do
you change the output?  I sometimes see missing ports, or missing punctuation
here and there...  What am I not considering here?

