Display Filter Reference: Snort Alerts

Protocol field name: snort

Versions: 2.4.0 to 4.2.5

Field name Description Type Versions
snort.alert.expertSnort alert detectedLabel2.4.0 to 4.2.5
snort.classAlert ClassificationCharacter string2.4.0 to 4.2.5
snort.contentContentCharacter string2.4.0 to 4.2.5
snort.content.not-matchedFailed to find content field of alert in frameLabel2.4.0 to 4.2.5
snort.generatorRule GeneratorUnsigned integer (32 bits)2.4.0 to 4.2.5 StatsCharacter string2.4.0 to 4.2.5 numberUnsigned integer (32 bits)2.4.0 to 4.2.5 of rulesUnsigned integer (32 bits)2.4.0 to 4.2.5 of rule filesUnsigned integer (32 bits)2.4.0 to 4.2.5 of alerts for this ruleUnsigned integer (32 bits)3.4.0 to 4.2.5 number for this ruleUnsigned integer (32 bits)2.4.0 to 4.2.5 of alerts detectedUnsigned integer (32 bits)2.4.0 to 4.2.5
snort.msgAlert MessageCharacter string2.4.0 to 4.2.5
snort.pcrePCRECharacter string2.4.0 to 4.2.5
snort.priorityAlert PriorityUnsigned integer (32 bits)2.4.0 to 4.2.5
snort.protocolProtocolCharacter string2.4.0 to 4.2.5
snort.raw-alertRaw AlertCharacter string2.4.0 to 4.2.5
snort.reassembled_fromSegment where alert was triggeredFrame number2.4.0 to 4.2.5
snort.reassembled_inReassembled frame where alert is shownFrame number2.4.0 to 4.2.5
snort.referenceReferenceCharacter string2.4.0 to 4.2.5
snort.revRule RevisionUnsigned integer (32 bits)2.4.0 to 4.2.5
snort.ruleRuleCharacter string2.4.0 to 4.2.5
snort.rule-filenameRule FilenameCharacter string2.4.0 to 4.2.5
snort.rule-ip-varIP variableLabel2.4.0 to 4.2.5
snort.rule-line-numberLine number within rules file where rule was parsed fromUnsigned integer (32 bits)2.4.0 to 4.2.5
snort.rule-port-varPort variable used in ruleLabel2.4.0 to 4.2.5
snort.rule-stringRule StringCharacter string2.4.0 to 4.2.5
snort.sidRule SIDUnsigned integer (32 bits)2.4.0 to 4.2.5
snort.uricontentURI ContentCharacter string2.4.0 to 4.2.5