Welcome to the Aanval Wiki. Snort, Suricata and Syslog Intrusion Detection, Situational Awareness and Risk Management.

Visit http://www.aanval.com/ for more information.

Unified2

From Aanval Wiki
Jump to: navigation, search

Created by Sourcefire, Unified2 is a IDS event file format from which programs such as Barnyard2 parse said events to other known and recognizable formats (Snort, MySQL, syslog, etc.).

Suricata writes only in Unified2 format, and Sourcefire has announced that the upcoming Snort release 2.9.3 will only write in Unified2, as the current version 2.9.2.3 writes in Unified2 or to a database.

Unified2 offers IPv6 support.