4.2.8CSV數(shù)據(jù)模塊\r\n利用CSV模塊,可以將輸出數(shù)據(jù)保存為CSV文件,可以將數(shù)據(jù)導(dǎo)入到其他的軟件中,如Excel等等。啟動(dòng)CSV模塊的語(yǔ)句模式如下:\r\noutput csv: <filename> <formatting_options>\r\n文件默認(rèn)被創(chuàng)建到/var/log/snort路徑下面,選項(xiàng)用來(lái)定義文件中儲(chǔ)存什么樣的信息以及以什么樣的順序儲(chǔ)存。\r\n例如,你用default作為格式選想那么告警的所有參數(shù)將被存儲(chǔ)在文件中:\r\noutput csv: csv_log default\r\n輸出文件的格式如下:\r\n07/23-18:24:03.388106 ,ICMP Packet with\r\nTTL=100,ICMP,192.168.1.100,,192.168.1.2,,0:2:3F:33:C6:98,0:E0:29:89:\r\n28:59,0x4A,,,,,,100,0,51367,60,20,8,0,,\r\n07/23-18:25:51.608106 ,GET\r\nmatched,TCP,192.168.1.2,1060,192.168.10.193,,0:E0:29:89:28:59,0:6:25\r\n:5B:29:ED,0x189,***AP***,0x55BCF404,0x8CBF42DD,,0x16D0,64,0,35580,37\r\n9,20,,,,\r\n07/23-18:25:52.008106 ,GET\r\nmatched,TCP,192.168.1.2,1061,192.168.10.193,,0:E0:29:89:28:59,0:6:25\r\n:5B:29:ED,0x1D0,***AP***,0x55628967,0x8D33FB74,,0x16D0,64,0,63049,45\r\n0,20,,,,\r\n07/23-18:25:52.478106 ,GET\r\nmatched,TCP,192.168.1.2,1061,192.168.10.193,,0:E0:29:89:28:59,0:6:25\r\n:5B:29:ED,0x1D0,***AP***,0x55628B01,0x8D33FC1B,,0x1920,64,0,63051,45\r\n0,20,,,,\r\n07/23-18:25:52.708106 ,GET\r\nmatched,TCP,192.168.1.2,1061,192.168.10.193,,0:E0:29:89:28:59,0:6:25\r\n:5B:29:ED,0x1EF,***AP***,0x55628C9B,0x8D33FCC1,,0x1D50,64,0,63053,48\r\n1,20,,,,\r\n每一行包括下面的字段: |