<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Snort parser in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200389#M62481</link>
    <description>&lt;P&gt;I think. I miss configure at parserConfig or miss snort pattern.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jun 2017 17:25:47 GMT</pubDate>
    <dc:creator>adroot16</dc:creator>
    <dc:date>2017-06-07T17:25:47Z</dc:date>
    <item>
      <title>Snort parser</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200384#M62476</link>
      <description>&lt;P&gt;
	I tested Snort alert and it's have log info following&lt;/P&gt;&lt;PRE&gt;[**] [1:10000001:1] ICMP test detected [**]
[Classification: Generic ICMP event] [Priority: 3]
06/06-14:54:02.125421 172.16.1.10 -&amp;gt; 172.16.1.20
ICMP TTL:126 TOS:0x0 ID:15052 IpLen:20 DgmLen:60
Type:8  Code:0  ID:1   Seq:1473  ECHO
&lt;/PRE&gt;&lt;P&gt;When I checked storm log and it's show&lt;/P&gt;&lt;PRE&gt;2017-06-07 09:39:41.083 o.a.s.d.executor [ERROR]
java.lang.IllegalStateException: Unable to parse message: 06/06-14:54:02.125421 172.16.1.10 -&amp;gt; 172.16.1.20
&lt;/PRE&gt;&lt;P&gt;Can you help me?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 13:38:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200384#M62476</guid>
      <dc:creator>adroot16</dc:creator>
      <dc:date>2017-06-07T13:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Snort parser</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200385#M62477</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/16340/adroot16.html" nodeid="16340"&gt;@Lee Adrian&lt;/A&gt;, can you check that you have re-configured your snort system to include year in the timestamp? This error could be the reason.&lt;/P&gt;&lt;P&gt;Check the Note section in this link - &lt;A href="https://docs.hortonworks.com/HDPDocuments/HCP1/HCP-1.1.0/bk_administration/content/supported_datasources.html" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/HCP1/HCP-1.1.0/bk_administration/content/supported_datasources.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 16:20:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200385#M62477</guid>
      <dc:creator>asubramanian</dc:creator>
      <dc:date>2017-06-07T16:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Snort parser</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200386#M62478</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/11832/asubramanian.html" nodeid="11832"&gt;@asubramanian&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I re-configured my snort system and It's show alert log.&lt;/P&gt;&lt;PRE&gt;[**] [1:10000001:1] ICMP test detected [**]
[Classification: Generic ICMP event] [Priority: 3]
06/07/17-16:37:15.044404 172.16.1.10 -&amp;gt; 172.16.1.20
ICMP TTL:126 TOS:0x0 ID:14129 IpLen:20 DgmLen:60
Type:8  Code:0  ID:1   Seq:1523  ECHO
&lt;/PRE&gt;&lt;P&gt;And I re-configured snort.json file&lt;/P&gt;&lt;PRE&gt;{
  "parserClassName":"org.apache.metron.parsers.snort.BasicSnortParser",
  "sensorTopic":"snort",
  "parserConfig": {
        "dateFormat" : "MM/dd/yy-HH:mm:ss.SSSSSS",
        "timeZone" : "America/New_York"
  }
}
&lt;/PRE&gt;&lt;P&gt;But it still fails.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 16:47:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200386#M62478</guid>
      <dc:creator>adroot16</dc:creator>
      <dc:date>2017-06-07T16:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Snort parser</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200387#M62479</link>
      <description>&lt;P&gt;Can you paste the error that you are seeing now? I am assuming you have restarted the snort topology.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 16:52:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200387#M62479</guid>
      <dc:creator>asubramanian</dc:creator>
      <dc:date>2017-06-07T16:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Snort parser</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200388#M62480</link>
      <description>&lt;P&gt;You check help me. please.&lt;/P&gt;&lt;PRE&gt;2017-06-07 17:09:32.589 o.a.m.p.s.BasicSnortParser [ERROR] Unable to parse message: [**] [1:10000001:1] ICMP test detected [**]
java.lang.IllegalArgumentException: Unexpected number of fields, expected: 27 in [**] [1:10000001:1] ICMP test detected [**]
        at org.apache.metron.parsers.snort.BasicSnortParser.parse(BasicSnortParser.java:148) [stormjar.jar:?]
        at org.apache.metron.parsers.interfaces.MessageParser.parseOptional(MessageParser.java:45) [stormjar.jar:?]
        at org.apache.metron.parsers.bolt.ParserBolt.execute(ParserBolt.java:123) [stormjar.jar:?]
        at org.apache.storm.daemon.executor$fn__6573$tuple_action_fn__6575.invoke(executor.clj:734) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.daemon.executor$mk_task_receiver$fn__6494.invoke(executor.clj:466) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.disruptor$clojure_handler$reify__6007.onEvent(disruptor.clj:40) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.utils.DisruptorQueue.consumeBatchToCursor(DisruptorQueue.java:451) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.utils.DisruptorQueue.consumeBatchWhenAvailable(DisruptorQueue.java:430) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.disruptor$consume_batch_when_available.invoke(disruptor.clj:73) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.daemon.executor$fn__6573$fn__6586$fn__6639.invoke(executor.clj:853) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.util$async_loop$fn__554.invoke(util.clj:484) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at clojure.lang.AFn.run(AFn.java:22) [clojure-1.7.0.jar:?]
        at java.lang.Thread.run(Thread.java:745) [?:1.8.0_77]
2017-06-07 17:09:32.594 o.a.s.d.executor [ERROR]
java.lang.IllegalStateException: Unable to parse message: [**] [1:10000001:1] ICMP test detected [**]
        at org.apache.metron.parsers.snort.BasicSnortParser.parse(BasicSnortParser.java:180) ~[stormjar.jar:?]
        at org.apache.metron.parsers.interfaces.MessageParser.parseOptional(MessageParser.java:45) ~[stormjar.jar:?]
        at org.apache.metron.parsers.bolt.ParserBolt.execute(ParserBolt.java:123) [stormjar.jar:?]
        at org.apache.storm.daemon.executor$fn__6573$tuple_action_fn__6575.invoke(executor.clj:734) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.daemon.executor$mk_task_receiver$fn__6494.invoke(executor.clj:466) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.disruptor$clojure_handler$reify__6007.onEvent(disruptor.clj:40) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.utils.DisruptorQueue.consumeBatchToCursor(DisruptorQueue.java:451) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.utils.DisruptorQueue.consumeBatchWhenAvailable(DisruptorQueue.java:430) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.disruptor$consume_batch_when_available.invoke(disruptor.clj:73) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.daemon.executor$fn__6573$fn__6586$fn__6639.invoke(executor.clj:853) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at org.apache.storm.util$async_loop$fn__554.invoke(util.clj:484) [storm-core-1.0.1.2.5.3.0-37.jar:1.0.1.2.5.3.0-37]
        at clojure.lang.AFn.run(AFn.java:22) [clojure-1.7.0.jar:?]
        at java.lang.Thread.run(Thread.java:745) [?:1.8.0_77]
Caused by: java.lang.IllegalArgumentException: Unexpected number of fields, expected: 27 in [**] [1:10000001:1] ICMP test detected [**]
        at org.apache.metron.parsers.snort.BasicSnortParser.parse(BasicSnortParser.java:148) ~[stormjar.jar:?]
        ... 12 more


&lt;/PRE&gt;</description>
      <pubDate>Wed, 07 Jun 2017 17:06:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200388#M62480</guid>
      <dc:creator>adroot16</dc:creator>
      <dc:date>2017-06-07T17:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: Snort parser</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200389#M62481</link>
      <description>&lt;P&gt;I think. I miss configure at parserConfig or miss snort pattern.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 17:25:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200389#M62481</guid>
      <dc:creator>adroot16</dc:creator>
      <dc:date>2017-06-07T17:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Snort parser</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200390#M62482</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/11832/asubramanian.html" nodeid="11832"&gt;@asubramanian&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Can you susgest help me?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 09:04:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200390#M62482</guid>
      <dc:creator>adroot16</dc:creator>
      <dc:date>2017-06-08T09:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Snort parser</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200391#M62483</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/16340/adroot16.html" nodeid="16340"&gt;@Lee Adrian&lt;/A&gt;, you need to setup your snort to output CSV alerts and then push those into the snort kafka topic. The parser reconfiguration should not be necessary.&lt;/P&gt;&lt;P&gt;See this &lt;A target="_blank" href="http://manual-snort-org.s3-website-us-east-1.amazonaws.com/node21.html#SECTION00366000000000000000"&gt;link&lt;/A&gt; on how to configure snort to output alert_csv.&lt;/P&gt;&lt;P&gt;Can you give this a try and let me know how it goes ?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 15:50:20 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200391#M62483</guid>
      <dc:creator>asubramanian</dc:creator>
      <dc:date>2017-06-08T15:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Snort parser</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200392#M62484</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/11832/asubramanian.html" nodeid="11832"&gt;@asubramanian&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I re-configured sucessfull. Thanks you.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 18:09:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Snort-parser/m-p/200392#M62484</guid>
      <dc:creator>adroot16</dc:creator>
      <dc:date>2017-06-08T18:09:57Z</dc:date>
    </item>
  </channel>
</rss>

