Display Filter Reference: Snort Alerts
Protocol field name: snort
Versions: 2.4.0 to 4.4.1
Back to Display Filter Reference
Field name | Description | Type | Versions |
---|---|---|---|
snort | Snort alert detected | Label | 2.4.0 to 4.4.1 |
snort | Alert Classification | Character string | 2.4.0 to 4.4.1 |
snort | Content | Character string | 2.4.0 to 4.4.1 |
snort | Failed to find content field of alert in frame | Label | 2.4.0 to 4.4.1 |
snort | Rule Generator | Unsigned integer (32 bits) | 2.4.0 to 4.4.1 |
snort | Global Stats | Character string | 2.4.0 to 4.4.1 |
snort | Match number | Unsigned integer (32 bits) | 2.4.0 to 4.4.1 |
snort | Number of rules | Unsigned integer (32 bits) | 2.4.0 to 4.4.1 |
snort | Number of rule files | Unsigned integer (32 bits) | 2.4.0 to 4.4.1 |
snort | Number of alerts for this rule | Unsigned integer (32 bits) | 3.4.0 to 4.4.1 |
snort | Match number for this rule | Unsigned integer (32 bits) | 2.4.0 to 4.4.1 |
snort | Number of alerts detected | Unsigned integer (32 bits) | 2.4.0 to 4.4.1 |
snort | Alert Message | Character string | 2.4.0 to 4.4.1 |
snort | PCRE | Character string | 2.4.0 to 4.4.1 |
snort | Alert Priority | Unsigned integer (32 bits) | 2.4.0 to 4.4.1 |
snort | Protocol | Character string | 2.4.0 to 4.4.1 |
snort | Raw Alert | Character string | 2.4.0 to 4.4.1 |
snort | Segment where alert was triggered | Frame number | 2.4.0 to 4.4.1 |
snort | Reassembled frame where alert is shown | Frame number | 2.4.0 to 4.4.1 |
snort | Reference | Character string | 2.4.0 to 4.4.1 |
snort | Rule Revision | Unsigned integer (32 bits) | 2.4.0 to 4.4.1 |
snort | Rule | Character string | 2.4.0 to 4.4.1 |
snort | Rule Filename | Character string | 2.4.0 to 4.4.1 |
snort | IP variable | Label | 2.4.0 to 4.4.1 |
snort | Line number within rules file where rule was parsed from | Unsigned integer (32 bits) | 2.4.0 to 4.4.1 |
snort | Port variable used in rule | Label | 2.4.0 to 4.4.1 |
snort | Rule String | Character string | 2.4.0 to 4.4.1 |
snort | Rule SID | Unsigned integer (32 bits) | 2.4.0 to 4.4.1 |
snort | URI Content | Character string | 2.4.0 to 4.4.1 |