Let's make use of Sawmill again, this time to parse snort logs:
- We will select Create New Profile, which will result in the following:
- Select Snort logs and then press Next, which will show us the log-detection process:
- On successfully detecting the log type, we will get the following options:
- Select Sourcefire Snort 2 format ...