Summary
In this chapter, we discussed the alert subsystem of Snort. We discussed the process that happens when there is a successful match for a signature. We discussed the role of the alert subsystem, that is, to create an alert when there is a successful identification of a malicious packet or session.
We looked at the various alert formats and looked at a few formats in detail. In the next chapter, we will explore OpenAppID.