This will log to stdout, so setup a loggin driver in your docker-compose, fx.:
logging:
driver: "syslog"
options:
tag: snort
syslog-address: "udp://Something:514"
Also this will pull the community rules at start/restart
docker run -t --rm --network host -e INTERFACE=ens192 -e HOME_NET=192.168.0.0/21 --cap-add=NET_ADMIN terpz/snort3:latest
or
version: '3'
services:
snort3:
network_mode: host
tty: true
image: terpz/snort3:latest
environment:
- INTERFACE=ens192
- HOME_NET=192.168.0.0/21
- IGNORESID=384
- TZ=Europe/Copenhagen
cap_add:
- NET_ADMIN
Example output:
Commencing packet processing
++ [0] ens192
{ "timestamp" : "09/09-11:24:28.102081", "iface" : "ens192", "src_addr" : "192.168.1.150", "dst_addr" : "192.168.4.104", "proto" : "ICMP", "action" : "allow", "msg" : "PROTOCOL-ICMP PING Windows", "priority" : 3, "class" : "Misc activity", "sid" : 382 }
{ "timestamp" : "09/09-11:24:28.102081", "iface" : "ens192", "src_addr" : "192.168.1.150", "dst_addr" : "192.168.4.104", "proto" : "ICMP", "action" : "allow", "msg" : "PROTOCOL-ICMP Unusual PING detected", "priority" : 2, "class" : "Information Leak", "sid" : 29456 }
{ "timestamp" : "09/09-11:24:28.102081", "iface" : "ens192", "src_addr" : "192.168.1.150", "dst_addr" : "192.168.4.104", "proto" : "ICMP", "action" : "allow", "msg" : "PROTOCOL-ICMP PING", "priority" : 3, "class" : "Misc activity", "sid" : 384 }
{ "timestamp" : "09/09-11:24:28.102145", "iface" : "ens192", "src_addr" : "192.168.4.104", "dst_addr" : "192.168.1.150", "proto" : "ICMP", "action" : "allow", "msg" : "PROTOCOL-ICMP Echo Reply", "priority" : 3, "class" : "Misc activity", "sid" : 408 }
{ "timestamp" : "09/09-11:24:39.853044", "iface" : "ens192", "src_addr" : "192.168.1.1", "src_port" : 53, "dst_addr" : "192.168.4.104", "dst_port" : 53336, "proto" : "UDP", "action" : "allow", "msg" : "PROTOCOL-DNS SPOOF query response with TTL of 1 min. and no authority", "priority" : 2, "class" : "Potentially Bad Traffic", "sid" : 254 }
{ "timestamp" : "09/09-11:24:40.338680", "iface" : "ens192", "src_addr" : "192.168.1.1", "src_port" : 53, "dst_addr" : "192.168.4.104", "dst_port" : 34686, "proto" : "UDP", "action" : "allow", "msg" : "PROTOCOL-DNS SPOOF query response with TTL of 1 min. and no authority", "priority" : 2, "class" : "Potentially Bad Traffic", "sid" : 254 }
Based on: https://github.com/jgru/docker-snort3
Content type
Image
Digest
sha256:85b0e36d8…
Size
280.4 MB
Last updated
about 4 years ago
docker pull terpz/snort3