Protocol field name: snort
Versions: 2.4.0 to 4.6.0
Back to Display Filter Reference
| Field name | Description | Type | Versions |
|---|---|---|---|
| snort | Snort alert detected | Label | 2.4.0 to 4.6.0 |
| snort | Alert Classification | Character string | 2.4.0 to 4.6.0 |
| snort | Content | Character string | 2.4.0 to 4.6.0 |
| snort | Failed to find content field of alert in frame | Label | 2.4.0 to 4.6.0 |
| snort | Rule Generator | Unsigned integer (32 bits) | 2.4.0 to 4.6.0 |
| snort | Global Stats | Character string | 2.4.0 to 4.6.0 |
| snort | Match number | Unsigned integer (32 bits) | 2.4.0 to 4.6.0 |
| snort | Number of rules | Unsigned integer (32 bits) | 2.4.0 to 4.6.0 |
| snort | Number of rule files | Unsigned integer (32 bits) | 2.4.0 to 4.6.0 |
| snort | Number of alerts for this rule | Unsigned integer (32 bits) | 3.4.0 to 4.6.0 |
| snort | Match number for this rule | Unsigned integer (32 bits) | 2.4.0 to 4.6.0 |
| snort | Number of alerts detected | Unsigned integer (32 bits) | 2.4.0 to 4.6.0 |
| snort | Alert Message | Character string | 2.4.0 to 4.6.0 |
| snort | PCRE | Character string | 2.4.0 to 4.6.0 |
| snort | Alert Priority | Unsigned integer (32 bits) | 2.4.0 to 4.6.0 |
| snort | Protocol | Character string | 2.4.0 to 4.6.0 |
| snort | Raw Alert | Character string | 2.4.0 to 4.6.0 |
| snort | Segment where alert was triggered | Frame number | 2.4.0 to 4.6.0 |
| snort | Reassembled frame where alert is shown | Frame number | 2.4.0 to 4.6.0 |
| snort | Reference | Character string | 2.4.0 to 4.6.0 |
| snort | Rule Revision | Unsigned integer (32 bits) | 2.4.0 to 4.6.0 |
| snort | Rule | Character string | 2.4.0 to 4.6.0 |
| snort | Rule Filename | Character string | 2.4.0 to 4.6.0 |
| snort | IP variable | Label | 2.4.0 to 4.6.0 |
| snort | Line number within rules file where rule was parsed from | Unsigned integer (32 bits) | 2.4.0 to 4.6.0 |
| snort | Port variable used in rule | Label | 2.4.0 to 4.6.0 |
| snort | Rule String | Character string | 2.4.0 to 4.6.0 |
| snort | Rule SID | Unsigned integer (32 bits) | 2.4.0 to 4.6.0 |
| snort | URI Content | Character string | 2.4.0 to 4.6.0 |